Tuesday, September 6, 2011

Audit of hacked Certificate Authority reveals poor security

Recently, the Dutch Certificate Authority (CA) DigiNotar was hacked and brought with it a huge scandal since it was proven that hackers had successfully created fake Google SSL certificates.

DigiNotar

It began with a fake Google certificate that had been used by someone to impersonate Google. SSL certificates are used to verify a domains ownership but are also used to encrypt the data sent between the client and the certificate holder. The fake certificate caused some stir within the IT community and raised the question whether or not to trust CA's since this is a second CA that has been hacked in the past year. The false certificate was traced back to DigiNotar and was discussed on the web and also in news stories but DigiNotar first admitted they have had a security breach a couple of days after this was revealed.

DigiNotar stated that the attack happened on July 19th and all the affected certificates had been withdrawn. But clearly their own audit of the security breach had not been thorough enough since the faked Google certificate suddenly appeared. And later there had been found more certificates in the wild and it quickly revealed that more serious certificates had been compromised including CIA, MI6 and Mossad. All major browsers have stated that they will issue an update blocking all of DigiNotar's certificates.

With the scandal that hit the CA the Dutch government chose to do an external audit of the breach to determine how this could have happened. The security auditors Fox-IT who where hired to examine the compromised servers revealed that the level of security within DigiNotar's system had been ridiculously low and pointed out such insecurities as,

  1. A single administrator account on a windows machine owned all the certificates.
  2. The administrator account was protected by a weak password that was easily brute-forced.
  3. The tools used by the hacker would have been detected by anti-virus, had it been present.
  4. The software running on the server was outdated and unpatched.

Those are some of the problems listed by Fox-IT and it really shows the lack of DigiNotar's responsibility and common sense. A Certificate Authority provides a service of security that is used to verify a website is what it claims to be and is used to encrypt credit card information on payments and to encrypt the data sent between citizens and public institutions and much more. I only ask, how can there be such an insecure system to govern the certificates? One would expect such companies to at least know common practices when guarding data you don't want to be compromised.

As of now almost 99% of the queries to the false certificates have originated from Iran which make the Iranian government prime suspect of this attack. Iran was also one of the suspects when Comodo (a South-American CA) was hacked earlier this year.

Filth - Requiem For A Dream (Dubstep Remix)


Awesome dubstep track I found today. The Original song is the theme song of the movie Requiem For A Dream - also an awesome movie that I would recommend everyone to watch.

But listen to this masterpiece!

Saturday, September 3, 2011

Dutch journalist hacks transit card

In Netherlands, a reporter has been trying to stress out the outrageously insecure card software that the Dutch subway system uses for their transit cards. The transit card is designed as a kind of debit card where one can add money to the card and then travel with the subway system by paying with the card.



The card is delivered by the company Trans Link Systems that also oversees the transit card system. It functions by using a RFID chip that you wave in front of a proximity sensor that registers a travels start and stop, and then withdraws the amount of money according to the distance traveled. The main security issue exists in the encryption that the card is protected by, namely the Crypto-1 algorithm which was cracked in 2008, for more information see this.
   Now, armed with a cheap RFID reader/writer, which you can get for less than $40, you can easily access the information stored on the card and edit it as you wish. Moreover, the software that is used for monitoring the cards is not designed to detect unusual activity or even tampering with the card. That was exactly what the reporter/hacker Brenno de Winter proved by using a hacked card for 3 weeks without being detected even though he intentionally tried to get caught by inserting mutliple check-outs from the same airport with a 3-minute interval, which is practically impossible without some sort of teleportation. And that's not even the worst part. The technique not only allows you to insert checkouts but you could also add an unlimited amount of money to the card which means one could travel for free within the Dutch subway system with a hacked card. A potential exploiter could also use a portable RFID reader that would steal the information on other peoples cards just by walking past them and then print the information to his own card.
   You don't even have to be a hacker, let alone a techsavvy person,  to successfully hack your card since the tools needed only includes the cheap RFID reader/writer and software that easily can be downloaded from the internet.


Now the reporter Brenno de Winter, is being sued by the transportation companies for fraud, and his goal of getting the vulnerabilities fixed is being draned down the toilet. The company only stated that it is illegal to hack your card and that there will be taken legal actions against exploiters.


Even though the cards security flaws are well known, the same solution is being implemented into the bus and subway system in Denmark, which already is many years behind schedule and many millions of dollars over budget because of adjustments that needed to be made so it would adapt to the already established systems in Denmark.


At time of writing, there still hasn't been taken any action nor is there any information available that they intend to fix the vulnerabilities in the current card software.