Ads 468x60px

Subscribe:

Social Icons

Mostrando entradas con la etiqueta security. Mostrar todas las entradas
Mostrando entradas con la etiqueta security. Mostrar todas las entradas

miércoles, 17 de septiembre de 2014

Over three-quarters of mobile apps will fail security tests by 2015

New research by analysts at Gartner shows that more than 75 percent of mobile apps are set to fail basic security tests by 2015.
This is a particular worry for enterprises as employees may download software from app stores. These apps offer minimal or no security assurances but are able to access sensitive business data and violate company security policy.

"Enterprises that embrace mobile computing and bring your own device (BYOD) strategies are vulnerable to security breaches unless they adopt methods and technologies for mobile application security testing and risk assurance," says Dionisio Zumerle, principal research analyst at Gartner. "Most enterprises are inexperienced in mobile application security. Even when application security testing is undertaken, it is often done casually by developers who are mostly concerned with the functionality of applications, not their security".

Existing security vendors will need to modify their approach and their products in order to adapt to these new threats. As well as testing the client layer -- the app on the mobile itself -- there's also a need to look at the server layer. Code and user interfaces of server side applications need to be tested to ensure that data isn't leaked.

"Today, more than 90 percent of enterprises use third-party commercial applications for their mobile BYOD strategies, and this is where current major application security testing efforts should be applied," says Zumerle. "App stores are filled with applications that mostly prove their advertised usefulness. Nevertheless, enterprises and individuals should not use them without paying attention to their security. They should download and use only those applications that have successfully passed security tests conducted by specialized application security testing vendors".

Looking further ahead to 2017, Gartner predicts that the focus of security breaches will have shifted to tablets and smartphones. Already it says there are three attacks on mobile devices for every one on a desktop.
It also expects that by 2017 misconfiguration of apps rather than actual attacks will account for 75 percent of mobile breaches. Gartner recommends that enterprises focus on data protection on mobile devices by employing usable and efficient solutions like application containment.



lunes, 15 de septiembre de 2014

Three Things Apple Can Do to Fix iCloud’s Awful Security



Apple’s reality distortion field makes for epic product launches. But it doesn’t keep sext-snatching hackers out of your iCloud account.
As the glow of Apple’s new iPhones and watch announcements fades, the company has yet to fix the security issues that resulted in a highly public violation of its users’ privacy: the leak of dozens of nude photos of celebrities including Jennifer Lawrence and Kate Upton, seemingly stolen from iCloud backups. And as the photos spread across the web last week, the conversations on scummy forums devoted to hacked nudes like Anon-IB made clear that Apple’s security weaknesses were still being exploited.
Chief executive Tim Cook has vowed to tighten the company’s protections for its users’ private parts. Users will be sent an email when someone restores their iCloud account from a new device, a warning that Apple neglected to send in the past, he told the Wall Street Journal. And its two-factor authentication system, which requires the user to have access to a temporary code sent to his or her phone, will be extended to iCloud and more strongly suggested to users. Apple didn’t respond to a request for more information on the new measures, which are expected to kick in this week.
But Cook’s promised changes sound like band-aids, not fundamental fixes. Warning users after a hacker has already gained access to their account isn’t exactly reassuring. And practically speaking, the vast majority of users won’t turn on a technical-sounding feature that adds another hurdle to their login process. “I wouldn’t be surprised if the adoption rate remains at less than one percent, and people still get hacked,” says Nik Cubrilovic, a Sydney, Australia-based security consultant who wrote a deep analysis of the iCloud hack earlier this month. When Cubrilovic added two factor authentication to his own iCloud account, he says he waited three days for it to come into effect. “What’s the awareness rate? How many people are going to sign up and wait three days? But next time someone gets hacked, Apple can shift the blame. They can say ‘it’s out of our hands.’”
Instead of that security theater performance, Cubrilovic and others who have tracked Apple’s security nightmare suggest a few unorthodox changes that go to the root of iCloud’s leaks.

Kill the Security Question

Asking users about their “first job,” “first car” or “city where your parents met” to reset their password has long been a laughably weak link in authentication schemes. Those answers are far more easily guessed or dug up with research than a password—especially for celebrity stalkers or those hacking their acquaintances or ex-significant others. Password reset questions are the idiocy that led directly to the devastating hack of WIRED’s Mat Honan two years ago, and nothing has fixed them since.
Far safer is to require that users who forget their password retrieve a reset link from their email. And in the slim subset of cases where users no longer have access to that email address, their snail-mail addresses can serve as slower stand-ins, argues iOS forensics expert Jonathan Zdziarski. If Apple requires users to keep a physical mailing address on file, Apple could mail them a one-time recovery key. To cover the cost of the stamp, he suggests Apple even charge users the shipping costs. “If you’re daft enough to not only lose your password but also access to your email, you should have to pay 50 cents or a dollar to mail you that piece of paper,” Zdziarski says. “Call that the ‘stupid tax.’”

Make Password Delinquents Show Up in Person

Cornell computer security professor Ari Juels has a suggestion for a faster last resort recovery method: Demand that password amnesiacs prove their identity in person.
People are accustomed to having to prove their identity with physical documents, argues Juels, who recently left a position as chief scientist at authentication security firm RSA. And Apple already has a network of meatspace retail outlets across America and Europe. So it could require users who want to reset their password to show up at one of its Genius Bars to prove themselves. To extend the fix to places without Apple Stores (sorry Wyoming, Montana, and the Dakotas) Apple could partner with post offices and banks—what Juels describes as “authentication authorities.” The company even has some of those relationships already: As it announced last week, its Apple Pay system will require users to go to a cooperating bank branch to add a new credit card number to their phone.
Juels admits that showing up in person is less convenient than security questions. But faking physical identification is far harder than Apple’s paper-thin safeguards against digital impersonation. “For the moment, convenience is king, and it’s not convenient to show up at the Apple Store to recover your password,” says Juels. “But eventually the problem may be so acute that we do try physical presence.”

Make Two-Factor the Law of the Land

With those new recovery options in place, Apple could then make its two-factor authentication more than a fig leaf. Instead of merely allowing or even encouraging users to turn it on, it could make two-factor the default for all new accounts, suggests Cubrilovic. ”There’s practically no reason why they can’t do that,” he says.
Requiring a second device be used to generate temporary login codes would nix the risk of account takeovers even when users have weak passwords or fall for phishing attacks that trick them into giving up their credentials. (Sophisticated phishers could steal the temporary code, too. But they’d need to use it immediately, making the attack less practical.)
For existing users, Apple could aggressively remind them to set up the second-device security measure rather than offering polite suggestions. And Cubrilovic also calls for Apple to cut the three-day wait time to put that measure in place, which doesn’t exist with similar services from Twitter and Google.
The barrier until now to universal two-factor authentication has been the risk that users might be permanently locked out of their accounts if they lose their second device and also can’t access their email. But Zdziarski’s and Juels’ ideas of snail-mail and in-person password resets could solve those corner cases.
The full set of new security measures they suggest would require Apple to invest in serious new infrastructure and user education. But Zdziarski argues that Apple owes it to its customers to take their security seriously, rather than treat them as hackable dolts. “Apple is the biggest company in the world right now. They should already be implementing these solutions,” he says. “To some degree, they’ve underestimated the sensitivity of users’ data. If you value it, you’re going to need to take steps to protect it.”



Original post: http://www.wired.com/2014/09/three-things-apple-can-fix-iclouds-awful-security/

martes, 2 de septiembre de 2014

Apple ‘actively investigating’ alleged iCloud hack that led to celeb photo leak


After nearly 24 hours of silence, Apple has finally commented on the alleged iCloud hack that led to a massive leak yesterday of nude celebrity photos. The Cupertino-based company says that it is aware of the reports and is “actively investigating” the claim.
“We take user privacy very seriously and are actively investigating this report,” Apple spokeswoman Natalie Kerris told Recode in a statement. She did not, however, provide any additional details on the attack, or if iCloud was even the source of the photos.
For those that missed it, a treasure trove of photos showing high profile celebrities like actress Jennifer Lawrence and model Kate Upton in little to no clothing popped up in a thread on 4chan. The original poster said they were obtained via an iCloud hack.
Many of the women named in the leak have since spoken out on the the matter. Some of them, such as Victoria Justice, are disputing the authenticity of the photos, while others, including Jennifer Lawrence (well, her PR agent), have confirmed their legitimacy.
Earlier today, it was reported that Apple fixed a vulnerability in Find My iPhone, which allowed for brute force attacks on Apple ID passwords. It’s been speculated that this loophole may have played a part in yesterday’s scandal, but it has not been confirmed
 
Blogger Templates