Showing posts with label security and risk complaints online. Show all posts
Showing posts with label security and risk complaints online. Show all posts

Monday, March 13, 2017

Online Info Blog: Internet security company springs big data leak



People aren’t actually saying that every cloud has an unencrypted lining but they are saying that every website protected by the online security service Cloudflare has been leaking encrypted session and user data—including credit card numbers and passwords—for months now and that millions of affected website users should promptly change their passwords!

Cloudflare, which provides million of online servers/websites with firewall-like traffic-filtering to protect against malicious hacking exploits, such as distributed denial of service attacks, announced on February 23 that it had a long-standing internal memory leak flaw. Cloudflare called it a “parser bug”, while the Internet security community-at-large dubbed it “cloudbleed” for its similarity to the Heartbleed memory overflow bug of three years ago.

It’s comforting how everyone pays lip service to security

The memory leak flaw was brought to Cloudflare’s attention on February 17 by Tavis Ormandy from Google’s Project Zero, which is tasked with finding such hidden code flaws.

World’s platform for change asks you to change your password

Change.org, which hosts millions of online petitions and is one of Cloudflare’s clients, sent out the following vaguely worded email on Saturday (February 25) to all registered users (including myself) recommending that we all change our passwords immediately:

We want you to feel safe when using our services and we have been monitoring this situation closely to ensure it does not affect our users. If you are ever in doubt about the security of your accounts with us, feel free to contact Change·org directly through our Help Center.

In fact, no one is suggesting that there is any evidence that any of these potential memory leaks from hundreds of millions (if not billions) of encrypted web sessions have been exploited by anyone. But it’s a good idea to “refresh” your passwords every so often, regardless of external evidence.
You can cry “Heartbleed”, or “Wolf”, only so many times!

Three things can be assumed to happen as a result of this latest Internet security bug. Firstly, all website users affected will receive a direct notification advising them of the fact and recommending that they change their passwords.

Secondly, the memory leak bug will be fixed.

And thirdly, most Internet users will conclude that this latest dire warning of an Internet security flaw affecting millions and millions of users is much ado about nothing—just like every similar warning of the last few years (not to mention that “world-ending” Y2K bug of  the year 2000).

After all, unlike a few of the malicious Microsoft Windows viruses and worms of yesteryear, which visibly destroyed data and took down bazillions of Windows computers, the high-profile software bugs of recent years have appeared to be mostly hype as far as end users are concerned.

The marketing of Internet flaws—but at whom?

Not to say that security flaws are not exploited by malicious coders. And yes, there is online identity theft and online credit card fraud aimed at individuals but the later two categories are very fuzzily documented—with no reliable numbers of actual consumer losses to online fraud.

Sunday, March 12, 2017

Online Info Blog: Cloudflare Bug Spills Private Data Online


The source of the problem – which was discovered accidentally by Google Project Zero bod, Tavis Ormandy – was a memory leak caused by a broken HTML parser chain.
However, it was compounded by the fact that leaked data was then cached by search engines.
The leaked data included “private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data,” Cloudflare CTO, John Graham-Cumming explained in a lengthy blog post.
“We quickly identified the problem and turned off three minor Cloudflare features (email obfuscation, Server-side Excludes and Automatic HTTPS Rewrites) that were all using the same HTML parser chain that was causing the leakage. At that point it was no longer possible for memory to be returned in an HTTP response,” he added.
Although Graham-Cumming claimed the bug was fixed globally in under seven hours, it may have been leaking highly sensitive data for months.
“The greatest period of impact was from February 13 and February 18 with around one in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests),” he added.
In fact, given the extent of the info cached by search engines, Cloudflare clients will now be under pressure to inform their own customers of the extent of the privacy snafu.
“The examples we're finding are so bad, I cancelled some weekend plans to go into the office on Sunday to help build some tools to cleanup. I've informed Cloudflare what I'm working on,” said Ormandy.
“I'm finding private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings. We're talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything.”
Although he praised Cloudflare for its response to the issue, it’s also true the firm’s bug bounty offers little in the way of rewards for white hat researchers – free t-shirts, rather than money.
Former Google click fraud boss and current Shape Security CTO, Shuman Ghosemajumder, argued that it is “one of the widest exposures of confidential and sensitive consumer data ever observed.”
“This incident has many people suggesting that everyone in the world should change all of their passwords immediately,” he said.
“The total exposure is likely not that large – i.e., not all of your passwords have been compromised – but the problem is that almost any one of your passwords on over four million websites could have been compromised, so the safest course of action is to act as though all of your passwords were compromised.”
Kaushik Narayan, CTO at Skyhigh Networks, analyzed over 30 million enterprise users worldwide and found 99.7% of companies have at least one employee that used a Cloudbleed vulnerable cloud application.
“This means hackers could have stolen user passwords for these cloud applications – and may even have access to session keys exposed, while a session is live. But this user-data also revealed another surprise – out of 128 enterprise-ready applications that could have been compromised, only four were vulnerable,” he added.
“Cloudbleed is the latest in a string of vulnerabilities that should be of concern to enterprise IT security and a reminder us of the problems caused by user password reuse across corporate services and personal web sites and cloud services.”

Sunday, March 5, 2017

Online Info Blog: Avoid scams


The web can be a great place, but not everyone online has good intentions. Here are three simple ways to avoid scammers and stay safe on the web:

Beware of strangers bearing gifts

A message is probably up to no good if it congratulates you for being a website’s millionth visitor, offers a tablet computer or other prize in exchange for completing a survey or promotes quick and easy ways to make money or get a job (“get rich quick working from your home for just two hours a day!”). If someone tells you that you’re a winner and asks you to fill out a form with your personal information don’t be tempted to start filling it out. Even if you don’t hit the “submit” button, you might still be sending your information to scammers if you start putting your data into their forms.

If you see a message from someone that you know that doesn’t seem like them, their account may have been compromised by a cyber criminal who is trying to get money or information from you – so be careful how you respond. Common tactics include asking you to urgently send them money, claiming to be stranded in another country or saying that their phone has been stolen so that they cannot be called. The message may also tell you to click on a link to see a picture, article or video, which actually leads you to a site that might steal your information – so think before you click!

Do your research

When shopping online, research the seller and be wary of suspiciously low prices just like you would if you were buying something at a local shop. Scrutinise online deals that seem too good to be true. No one wants to get tricked into buying fake goods. People who promise normally non-discounted expensive products or services for free or at 90% off probably have malicious intent. If you use Gmail, you may see a warning across the top of your screen if you’re looking at an email that our system says might be a scam – if you see this warning, think twice before responding to that email.

Watch out for scams using the Google brand. Google does not run a lottery. We do not charge training fees for new employees – if you receive an email saying that you have been hired by Google but have to pay a training fee before you can start, it is a scam. Watch out for people claiming to sell cars using Google Wallet. Find out more about various scams using the Google brand.

When in doubt, play it safe

Do you just have a bad feeling about an ad or an offer? Trust your gut! Only click on ads or buy products from sites that are safe, reviewed and trusted.

Many online shopping platforms have trusted merchants/sellers programs. These sellers typically have a visible stamp of approval on their profiles. Make sure that the stamp or certificate is legitimate by reviewing the shopping platforms’ guidelines. If the platform doesn’t offer a similar program, take a look at the number of reviews and the quality of reviews on the seller.

Tuesday, February 28, 2017

Online Info Blog: The Austalian


BECOME A MEMBER TO GET ACCESS TO EVERY STORY
Subscribe for Leading National & World News
Plus, complimentary digital access to The Wall Street Journal.

Monday, February 20, 2017

Online Info Blog: BBB warns about Valentine’s Day scams



Flower Fails

Because of the amount of money that consumers are expected to spend this Valentine’s Day on flowers, consumers can be certain that scammers and unscrupulous businesses will also be looking to benefit. To ensure that a Valentine’s Day bouquet is delivered as planned, follow these scam savvy tips:

- Let the BBB guide purchases. Research trusted florists and gift shops, check out customer reviews, and look for scams at bbb.org.
- Pick up the phone or visit the shop. Even if ordering online, visit or chat with the brick-and-mortar shop prior to making a purchase. Discuss the arrangement you are looking for, inquire about guarantees and ask about delivery times. Don’t make a payment until the order is clearly outlined and always ask for a receipt.
- Watch for unsolicited calls and emails. This time of year, phishing scams spike for those looking to treat loved ones with flowers and gifts. Fake e-cards can carry viruses, and unsolicited emails claiming to require additional funds for gift delivery are common.

Beware of Cupid Cons

The Internet’s ability to connect people through social media and online dating has been a godsend for many single folks. But with that convenience come opportunities for scammers to prey on the love-struck.
This is a common narrative with many Valentine’s Day scams. An interesting stranger builds a fake relationship with an unsuspecting target through phone or video calls, texts and emails. Eventually, the scammer claims to be experiencing a financial hardship — or begs for funds to come visit the love-struck victim. After money is exchanged, the scammer cuts off contact. These types of scams are tricky because scammers know how to make people feel vulnerable and how to get them to do what they want.

How do you avoid a Cupid con? Looking out for the following red flags can help protect both your heart and wallet:

- Your new friend is a constant no-show. Traveling for business, house-sitting for an out-of-state friend, visiting family far away and other last-minute schedule changes are all common excuses scammers use to avoid meeting people face-to-face. An interested girl – or boyfriend would normally want to make time to get to know you better in person. So, if a new love interest is avoiding you, it’s time to get a little suspicious.

- Their social media profiles don’t match, are very new or are nonexistent. Contact information, pictures and background information the person shares with you should match what you see on their social media profiles. A shortage of online friends and contacts, stock photos and spelling/grammatical errors can be clues that you are being wooed by a scammer.

- They ask you for money. Asking for a loan from even the closest of friends can be uncomfortable (not to mention unwise), so why would a new love be boldly asking you for cash? From medical emergencies to claims of being robbed — a romantic scammer isn’t afraid to brazenly beg. Be particularly wary of anyone asking you to send funds via wire transfer or a gift card. And never give money or share banking information with someone that you have not met in person or don’t know very well.