Scrolling box

computer hardware

Breaking News

Social Icons

Recent Comments

Showing posts with label RSA. Show all posts
Showing posts with label RSA. Show all posts

Tuesday, March 11, 2014

RSA Conference speakers begin to bail, thanks to NSA

In the wake of last month's revelations that encryption firm RSA has been in cahoots with the NSA, several of the best-known security industry speakers cancel their regular appearances at the RSA Conference.
In the wake of last month's revelations that encryption firm RSA has been in cahoots with the NSA, several of the best-known security industry speakers cancel their regular appearances at the RSA Conference.
Actions have consequences, goes the old saying, and actions taken by the security firm RSA in December have come back to haunt it this week.
RSA Conference speakers begin to bail, thanks to NSA

Last month, it was revealed that RSA had accepted $10 million from the National Security Agency to  implement an intentional cryptographic flaw , commonly called a backdoor, in one of its encryption tools. Days later, Mikko Hypponen, chief technology officer of F-Secure with decades under his belt as a security researcher,  canceled his annual presentation  at the American-hosted RSA Conference, to be held in San Francisco in February.
Related stories:

In most-anticipated SXSW talk in years, Snowden fires up Austin
WikiLeaks' Julian Assange: NSA critics got lucky because agency had no PR strategy
Kill the Snowden interview, congressman tells SXSW
Edward Snowden to speak at South by Southwest
Klocwork: Our source code analyzer caught Apple's 'gotofail' bug

"I don't really expect your multibillion-dollar company or your multimillion-dollar conference to suffer as a result of your deals with the NSA," he said. "In fact, I'm not expecting other conference speakers to cancel."
The Finnish Hypponen cited nationality as the reason behind the cancellation of his talk but didn't expect others to follow his boycott. He didn't think American attendees would care enough to take action against an American company assisting the government in surveillance of non-American citizens.
Hypponen canceled his talk, "Governments as Malware Authors," in December. He updated his blog on January 8 to explain that he was also pulling out of a panel appearance on the security challenges in connecting previously unconnected devices to the Internet.
"I don't want to send mixed messages, so I have canceled all my appearances at RSA 2014," he said.
He said that he initially felt that the panel appearance was unconnected to his protest. He also confirmed that his company, F-Secure, would not be "speaking, sponsoring or exhibiting" at the conference.
The day before Hypponen canceled his talk in December, Josh Thomas, the "Chief Breaking Officer" at security firm Atredis, canceled his scheduled talk via Twitter.
Jeffrey Carr, another security industry veteran who works in analyzing espionage and cyber warfare tactics, took his cancellation a step further. Yesterday, he publicly called for a  boycott of the conference , saying that RSA had violated the trust of its customers.
At DefCon 19, F-Secure Chief Technical Officer Mikko Hyponnen shows off a 5.25-inch floppy that has on it the first personal computer virus.
(Credit: Seth Rosenblatt/CNET)
"I can't imagine a worse action, short of a company's CEO getting involved in child porn," Carr told CNET. "I don't know what worse action a security company could take than to sell a product to a customer with a backdoor in it."
While many have acknowledged on Twitter that RSA the conference and RSA the company are only loosely tied entities, Carr argued that the only way to get the company to listen was to hit it where it hurts: in the wallet.
"When you look back at incidents that changed institutions of power, they weren't changed by hacking from the inside," he said. "The only way you change a company, you force the board of directors, by hitting their profits."
Carr said that he waited until this week to announce his decision because he thought that RSA had made a correctable public relations error, not an unusual mistake for the company. RSA found itself in a  public relations imbroglio in 2011 , when information about its SecurID authentication tokens was stolen.
Jeffrey Carr
(Credit: Jeffrey Carr/Twitter)
When the company declined to address the NSA deal further, Carr said he was left with no choice but to cancel his presentation and advocate for a boycott.
The choice was not an easy one, he said. He was hoping that his relatively new company, Taia Global, would get a business boost from his RSA Conference session. His co-presenter,  Christopher Burgess , opted to continue the presentation.
Following Carr's announcement on Monday, several other RSA regulars joined the boycott. These include privacy attorney and former Electronic Frontier Foundation lawyer Marcia Hoffman; Mozilla privacy and public policy expert Alex Fowler; American Civil Liberties Union advocate and privacy expertChristopher Soghoian; Google security expert Adam Langley; and Google Chrome security engineer Chris Palmer; bringing the total boycotters to eight.
RSA declined to comment for this story.
"Hopefully, this will force RSA to fire their CEO and apologize, and they can reclaim the company that RSA was in the '90s, as far as it goes toward the integrity of their encryption," Carr said.
In the 1990s, RSA was instrumental in resisting NSA pressure to include encrypted NSA access to personal computers via the Clipper Chip.
Given the company's stance so far, it would have to take a cancellation from a luminary like Stephen Colbert, who's delivering the opening keynote presentation this year, before Carr and the other boycotters get what they want.
Read more ...

RSA: Cyberattack could put customers at risk

The company warns in open letter that information stolen in attack could be used to compromise SecurID authentication implementations.
Information about RSA's SecurID authentication tokens used by millions of people, including government and bank employees, was stolen during an "extremely sophisticated cyberattack," putting customers relying on them to secure their networks at risk, the company said today.
RSA Executive Chairman Art Coviello warns customers about a security breach that affects its SecurID authentication technology

"Recently, our security systems identified an extremely sophisticated cyberattack in progress being mounted against RSA," Executive Chairman Art Coviello, wrote in an open letter to customers, which was posted on the company's Web site.
"Our investigation has led us to believe that the attack is in the category of an Advanced Persistent Threat. Our investigation also revealed that the attack resulted in certain information being extracted from RSA's systems. Some of that information is specifically related to RSA's SecurID two-factor authentication products," the letter said.
"While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack," Coviello wrote. "We are very actively communicating this situation to RSA customers and providing immediate steps for them to take to strengthen their SecurID implementations."
The company said it has no evidence that other products are affected or that personally identifiable data on customers or employees was compromised. RSA, the security division of technology giant EMC, did not elaborate and a spokesman said he could not provide additional information at this time.
The tokens, of which 40 million have been deployed, and 250 million mobile software versions, are the market leader for two-factor authentication. They are used in addition to a password, providing a randomly generated number that allows a user to access a network.
The tokens are commonly used in financial transactions and government agencies; one source who asked to remain anonymous said SecurID users in those sensitive areas were scrambling to figure out what to do in light of the breach.

What exactly did the bad guys get?
Because it's unclear exactly what type of information was stolen, sources told CNET they could only speculate as to what the potential outcome could be for companies using the devices.

"It's hard to say [how serious the breach is] until we know the extent of what the bad guys got a hold of," said Charlie Miller, a principal analyst at consultancy Independent Security Evaluators. "Any time a security company gets broken into, it reminds you that it could happen to anybody."
He used to work for a financial services firm that "basically ran everything on" SecurID, he said. "They would be very unhappy if they found out" it could be compromised somehow.
"The real story here is what was stolen. It definitely seems mysterious," said Ravi Ganesan, an operating partner at The Comvest Group and former founder and CEO of single sign-on provider TriCipher. "SecurID is a token authenticator device that flashes a new number every 60 seconds. The number is calculated from two things, a 'secret seed' unique to that device and the time of day. So your one-time password is output of [that] algorithm."
RSA has historically kept their algorithm secret, but that is not a good defense against a sophisticated attacker who could get a software version of the token or the back-end server and reverse engineer the code, Ganesan said. "So what on earth could have been stolen? I certainly hope RSA did not put some back door into the software and that was what got stolen."
While details were scarce, hints about the breach could be gleaned from a message to customers filed with the SEC. It recommended that customers increase focus on security for social-media applications and Web sites accessed by anyone with access to their critical networks; enforce strong password and PIN policies; as well as remind employees to avoid opening suspicious e-mails and providing usernames or other credentials to people without verifying the person's identity as well as avoid complying with e-mail or phone-based requests for such information.
Additionally, the message said customers should pay special attention to securing their active directories and use two-factor authentication to control access to them; watch closely for changes in user privilege levels and access rights; harden monitor and limit remote and physical access to infrastructure that hosts critical security software; shore up practices against social-engineering attacks; and update security products and patch operating system software.

Advanced Persistent Attacks often target source code and other information useful in espionage and involve knowledge of the company's network, key employees, and workings. Attackers use social engineering and exploits hidden in e-mail and other messages to sneak keyloggers and other snooping tools onto employees' computers. Google announced last year that it and other companies had been targeted in such an attack and it later came out that attackers used an unpatched hole in Internet Explorer to get into the company computers. Google said at the time that intellectual property was stolen and that the attacks appeared to originate in China.
Read more ...

An Open Letter to the Chiefs of EMC and RSA

23rd of December 2013


An Open Letter to:
Joseph M. Tucci - Chairman and Chief Executive Officer, EMC
Art Coviello - Executive Chairman, RSA



Dear Joseph and Art,

I don't expect you to know who I am.

I've been working with computer security since 1991. Nowadays I do quite a bit of public speaking on the topic. In fact, I have spoken eight times at either RSA Conference USA, RSA Conference Europe or RSA Conference Japan. You've even featured my picture on the walls of your conference walls among the 'industry experts'.

On December 20th, Reuters broke a story alleging that your company accepted a random number generator from the National Security Agency, and set it as the default option in one of your products, in exchange of $10 million. Your company has issued a statement on the topic, but you have not denied this particular claim. Eventually, NSA's random number generator was found to be flawed on purpose, in effect creating a back door. You had kept on using the generator for years despite widespread speculation that NSA had backdoored it.

As my reaction to this, I'm cancelling my talk at the RSA Conference USA 2014 in San Francisco in February 2014.

Aptly enough, the talk I won't be delivering at RSA 2014 was titled "Governments as Malware Authors".

I don't really expect your multibillion dollar company or your multimillion dollar conference to suffer as a result of your deals with the NSA. In fact, I'm not expecting other conference speakers to cancel. Most of your speakers are American anyway – why would they care about surveillance that's not targeted at them but at non-americans. Surveillance operations from the US intelligence agencies are targeted at foreigners. However I'm a foreigner. And I'm withdrawing my support from your event.

Sincerely,

Mikko Hypponen
Chief Research Officer
F-Secure

—————

Updated to add on the 8th of January 2014:

I was scheduled to deliver a talk at and participate in an FTC panel at the RSA Conference USA 2014.

Initially I only canceled my talk, as I didn't want to punish the FTC which had nothing to do with the events I was protesting about. However, partial participation sends mixed messages. I don't want to send mixed messages, so I have canceled all my appearances at RSA 2014. I'm sure the FTC will understand.

I can also confirm that F-Secure is not speaking, sponsoring or exhibiting at RSA Conference USA 2014.

While I am glad to see that many other speakers have decided to cancel their appearances at RSA 2014 in protest, I don't want to portray myself as a leader of a boycott. I did what I felt I had to do. Others are making their own decisions.

I have declined every interview on the topic and will continue to do so. This open letter says everything I want to say on this.

Mikko
Read more ...

Security firm RSA took millions from NSA: report

The National Security Agency paid $10 million to the security firm RSA to implement intentionally flawed encryption, according to a new report.
An RSA SecurID key fob

What's an encryption backdoor cost? When you're the NSA, apparently the fee is $10 million.
Intentional flaws created by the National Security Agency in RSA's encryption tokens werediscovered in September, thanks to documents released by whistleblower Edward Snowden. It has now been revealed that RSA was paid $10 million by the NSA to implement those backdoors, according to a new report in Reuters.
Related stories:

In most-anticipated SXSW talk in years, Snowden fires up Austin
WikiLeaks' Julian Assange: NSA critics got lucky because agency had no PR strategy
Kill the Snowden interview, congressman tells SXSW
Edward Snowden to speak at South by Southwest
Klocwork: Our source code analyzer caught Apple's 'gotofail' bug

Two people familiar with RSA's BSafe software told Reuters that the company had received the money in exchange for making the NSA's cryptographic formula as the default for encrypted key generation in BSafe.
"Now we know that RSA was bribed," said security expert Bruce Schneier, who has been involved in the Snowden document analysis. "I sure as hell wouldn't trust them. And then they made the statement that they put customer security first," he said.
RSA, now owned by computer storage firm EMC Corp, has a long history of entanglement with the government. In the 1990s, the company was instrumental in stopping a government plan to include a chip in computers that would've allowed the government to spy on people.
It has also had its algorithms hacked before, as has RSA-connected VeriSign.
The new revelation is important, Schneier said, because it confirms more suspected tactics that the NSA employs.
"You think they only bribed one company in the history of their operations? What's at play here is that we don't know who's involved," he said.
Other companies that build widely-used encryption apparatus include Symantec, McAfee, and Microsoft. "You have no idea who else was bribed, so you don't know who else you can trust," Schneier said.
In a statement issued Sunday, RSA said it "categorically" denied recent reports.
"We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have openly publicized it," the company said in a statement. "Our explicit goal has always been to strengthen commercial and government security."

The statement goes on to rebut a number of claims, including that the company knowingly introduced a flawed numbers generator into its encryption libraries.
Read more ...
THam khảo: Đầu thu DVB T2 | giàn phơi, lắp đặt giàn phơi quần áo hay giá giàn phơi thông minh tốt nhất cả nước