latest updates from easySERVICE™
Last week was an utter disaster for security. Superfish. Untrustworthy hardware. Easily hacked cars. FreeBSD’s random number generator. Security’s been in the spotlight ever since Edward Snowden’s revelations about the NSA’s extensive spying program, but by every measure, this week was a doozy. There were no fewer than four—count them, four—major, critical security issues revealed over the past few days. Any one would’ve been a major deal by itself. Together, it’s enough to make you want to curl up in a ball in the corner.
Got you tinfoil hat ready? You’re going to need it. Let’s start with the security disaster that popped up first: Utterly unstoppable malware that can’t be stopped by anything short of physically destroying your hard drive.
Hard drive hell
Late last Monday, Kaspersky Lab revealed details about the Equation Group, an incredibly advanced team of hackers that have been operating for at least a decade. Equation’s attacked targets in dozens of countries across the globe—including the U.S.—and evidence strongly suggests it’s state-sponsored. But the terrifying part is its sophisticated malware.
Equation uses malware that actually digs deep into the firmware of your physical hard drive, and is impossible to remove once installed. Installing a clean operating system or fully formatting your drive doesnothing. The only way to rid yourself of the malware is to hammer a spike through the drive and chuck it in the trash. PCWorld’s Equation Group report has more details, including information about susceptible drive models.
FreeBSD’s random number generator
While the world was still reeling from that revelation, another security disaster struck Tuesday. It turns out that the bleeding-edge version of FreeBSD, dubbed –CURRENT, had been using a borked random number generator that spit out not-so-random numbers for the past four months.
So what? Well, encryption tools rely on that RNG to create keys that unlock the encryption.Any cryptographic keys created during the affected time frame have to be considered unsafe due to the non-random material, and regenerated. Fortunately, the flaw was plugged at the time the announcement was made and the stable version wasn’t affected.
Last Wednesday, researchers discovered that since mid-2014, Lenovo PCs had adware called Superfish preinstalled on them. Superfish itself is a mere nuisance; the true risk came from a self-signed root certificate it installed in Windows to essentially hijack all secure internet traffic to inject ads on webpages. That’s known as a man-in-the-middle attack, folks. Worse, all infected PCs used thesame certificate on every affected system, using a weak, discontinued form of encryption; unsurprisingly, researchers quickly cracked it. Malicious hackers could easily use the vulnerability to attack you. The US government issued an alerttelling users to remove Superfish.
Lenovo’s contrite CTO quickly released a tool to remove Superfish and its rogue cert. Other vendors, including Microsoft, did the same, though not all fully eliminate the infection. PCWorld’s guide to Superfish removal can walk you through full, manual eradication.
All your SIMS are belong to us
In the midst of the Superfish furor, a new Snowden bombshell dropped last Thursday. A joint team comprised of U.S. NSA and U.K GCHQ agents have hacked into the computer network of Gemalto, the world’s biggest maker of smartphone SIM cards, and swiped the encryption keys for those cards. And they’ve been inside Gemalto’s network for years, as the Snowden slide was from 2010.
With those keys, government agents would be able to monitor mobile communicationswithout warrants, wire taps, or approval from foreign governments or carriers. They can listen to almost anything without outside permission, essentially. Roughly 450 mobile carriers, including AT&T, T-Mobile, Verizon Wireless, and Sprint, use Gemalto’s SIM cards.
Hand over the car!
Friday was pretty quiet on the security front, and understandably so, given the events of the four days prior. But one smaller scale, yet no less terrifying incident blipped on the radar: PCWorld reported how a 14-year old teen built a device from $15 worth of parts from Radio Shack that was able to wirelessly connect to a car’s internal computer network and control various functions.
Maybe it’s a good thing Radio Shack’s shutting its doors. (Actually, it’s still a shame.) Regardless, repeated demonstrations like this are why we keep clanging the warning bell about smart device security concerns.
Source: Associated Press