Subscribe:

Wednesday, 6 June 2012

6 keys to SSL and choosing the right cloud provider

Cloud computing is quickly changing the IT landscape, perhaps most prominently in healthcare.

But, according to a recent whitepaper by digital certificate provider GeoTrust, cloud services also pose "significant potential risks for enterprises that must safeguard corporate information assets while complying with a myriad of industry and government regulations."

With that said, GeoTrust helped outline six keys to understanding SSL and choosing the right cloud provider for you. 

1. Recognize the additional security challenges cloud technologies pose. 
Although there are obvious benefits of cloud technology, compliance and data privacy have slowed enterprise adoption, according to the report. "An IDC survey of IT executives reveals that security is the #1 challenge facing IT cloud services," it read. The report added that Gartner Research identified seven specific areas of security risk associated with enterprise cloud computing, and organizations should consider several of them when selecting a provider. They include access privileges, regulatory compliance, data location, and monitoring and reporting. "To reap the benefits of cloud computing without increasing security and compliance risks, enterprises must ensure they work only with trusted service providers that can address these and other cloud security challenges," it read. "What's more, when enterprises move from using just one cloud-based service to using several from different providers, they must manage all these issues across multiple operators."

2. Learn the ins and outs of SSL. Secure socket layer (SSL) is a security protocol used by Web browsers and servers to help users protect data during transfer. According to the report, it is the standard for establishing trusted exchanges of information over the Internet. "Without the ubiquity of SSL, any trust over the Internet simply would not be possible," it read. SSL delivers two services that help solve some cloud security issues, such as SSL encryption and establishing a trusted server and domain. Understanding the "SSL handshake," said the report, means knowing the importance of public and private key pairs as well as verified identification information. "[I]t can begin a secure session that protects data privacy and integrity," the report read.

3. Take steps to ensure data segregation and secure access. Data segregation risks are "ever-present" in cloud storage, according to the report. "With traditional onsite storage, the business owner controls both exactly where the data is located and exactly who can access it," it read. "In a cloud environment, that scenario is fundamentally changed; the cloud service provider controls here the servers and the data are located." But a proper implementation of SSL can secure sensitive data. To ensure this, the report advised a potential cloud provider should provide three things: encryption, authentication, and certificate validity. "Businesses should require their cloud provider to use a combination of SSL and servers that support … 128-bit session encryption," it read. "[They] also should demand that sever ownership be authenticated before one bit of data transfers between servers."

4. Keep regulatory compliance in mind. "When it comes to secure and confidential data, businesses are burdened with a slew of regulations," read the report, with HIPAA being the most notable for healthcare organizations. "When an organization outsources IT to a cloud service provider, the organization is still responsible for maintaining compliance with [HIPAA] and any other applicable regulations – and possibly more depending on where the servers and the data are at any given moment." The report mentioned since the enterprise IT manager can't rely solely on the cloud provider to meet requirements, he/she should require the provider to seek some compliance oversight. "Cloud computing providers who refuse to undergo external audits and security certifications are signaling that customers can only use them for the most trivial functions," the report read.

5. Know that not all SSL is created equal. The "chain of trust" when employing a cloud provider should also extend to their security provider, according to the report. "The cloud vendor's security is only as good as the reliability of the security technology they use," it read. Furthermore, organizations need to make sure their cloud provider uses an SSL certificate that can't be hacked. In addition to ensuring the SSL comes from an authorized third party, they should demand security requirements such as a certificate authority that safeguards its global roots, a certificate authority that maintains a disaster recovery backup, a chained hierarchy supporting their SSL certificated, global roots using new encryption standards, and secure hashing using the SHA-1 standard, "to ensure that the content of certificated can't be tampered with."

6. In the end, go with what you know. "SSL is a proven technology and a keystone of cloud security," the report read. "When an enterprise selects a cloud computing provider, the enterprise should consider the security options selected by that cloud provider." Knowing that a cloud provider uses SSL, said the report, can go a long way toward establishing confidence. Also, when selecting a cloud service provider, enterprises should be very clear with their partners regarding handling and mitigation of risk factors not addressable by SSL. "Cloud providers should be using SSL from an established, reliable and secure independent certificate authority," it read.

Source:healthcareitnews.com

Sunday, 3 June 2012

Flame signed with Microsoft certs

Microsoft has issued an emergency patch revoking digital certificates used to sign the Flame malware.

The patch revoked three intermediate Microsoft certificates used in active attacks to “spoof content, perform phishing attacks, or perform man-in-the-middle attacks”.

Microsoft also killed off certificates that were usable for code signing via Microsoft’s Terminal Services licensing certification authority (CA) that ultimately “chained up” to the Microsoft Root Authority.

The authority issued certificates for users to authorise Remote Desktop services in their enterprises.

Flame (Worm.Win32.Flame) had existed since 2010 and spread via removable media, according to the CERT, and by exploiting a patched Microsoft printer hole -- the same tapped by Stuxnet. It contained a backdoor and trojan and had worm-like features, allowing it to replicate in a local network and on removable media if it is commanded so.

Components of the sophisticated Flame malware were signed by the certificates using “an older cryptography algorithm [that] could be exploited and then be used to sign code as if it originated from Microsoft”, Microsoft security response centre senior director Mike Reavey said in an advisory.

The bugged algorithm “provided certificates with the ability to sign code, thus permitting code to be signed as if it came from Microsoft”.

“Now things may make sense with the Flame hoopla: It used the fake, but ‘valid’, MSFT certificate,” SANS Institute chief research officer Joannes Ullrich said in a tweet.

The bulletin did not specify who accessed the certificates.

The thumbprints of the untrusted certificates:

Certificate
Thumbprint

Intermediate PCA
2a 83 e9 02 05 91 a5 5f c6 dd ad 3f b1 02 79 4c 52 b2 4e 70
Intermediate PCA
3a 85 00 44 d8 a1 95 cd 40 1a 68 0c 01 2c b0 a3 b5 f8 dc 08

Registration Authority CA (SHA1)
fa 66 60 a9 4a b4 5f 6a 88 c0 d7 87 4d 89 a8 63 d7 4d ee 97

Source: Scmagazine.com.au

Wednesday, 23 May 2012

Symantec conference puts focus on mobile security

At its annual Symantec Vision conference attended by enterprise customers and business partners, Symantec laid out its management and security product strategy for mobile endpoint devices, including the iPhone, iPad and Google Android devices.

Symantec is offering a choice between two approaches to establishing management and security on Apple iOS and Android devices. The first, Symantec Mobile Manager, is its primary mobile device management (MDM) platform for enrolling corporate mobile devices and managing them. The second, for what's defined as mobile application management, is seen as especially useful for companies embracing the bring-your-own-device (BYOD) trend because it allows IT managers to isolate mobile apps and their data according to whether they are for corporate or personal use.

IN THE NEWS: iPhones, Android devices hot targets among 50,000 network attacks on California university

This second mobile application management choice, available in either a cloud-based or on-premises approach to manage iOS, Android and HTML5 apps, is based on Symantec's recent acquisition of Nukona. Brian Duckering, senior manager of product marketing for enterprise mobility at Symantec, says Symantec is retiring the Nukona name.

About the BYOD phenomenon, Duckering said, "Some companies want you to bring your own device. But the problem comes in highly regulated industries with more risk aversion. The policies they'd put in place on a device would be restrictive, such as restricting Facebook or use of a camera, for instance." These are the kind of controls that could be applied through mobile application management, which would also let you apply authentication and encryption controls to each app specifically.

When it comes to corporate-owned devices, "people typically start with MDM," said Duckering. The choice is becoming to manage the device or manage the app, though some organizations that are large enough could have cause to do both.

Symantec also announced:

- Symantec Data Loss Prevention for Mobile, which already supports iPad, has added support for iPhone.

- Symantec Certificate Intelligence Center for Mobile, an addition to Symantec's SSL certificate management service for tracking Web-based and internal certificates. CIC for Mobile is available on Apple iPad.

- For developers, Symantec code signing for Android, a tool for digitally signing their .APK files for the Android platform. The cloud-based service allows developers to securely manage their certificate keys and store their signed applications. It's said to be the first dedicated Android Root certificate from a security vendor.

source: Networkworld.com

Monday, 21 May 2012

Secure Certificate Industry Records Largest Growth in 12 Months

Go Daddy is the world's largest provider of net-new SSL Certificates and is growing at the industry's fastest rate, according to Netcraft's latest Secure Server Survey.
 
Overall, growth in the SSL industry reflected the biggest gains in the last 12 months. Go Daddy was at the top of the list, having added more than 33 thousand SSL Certificates to its portfolio in the last month. Additionally, Go Daddy accounted for more than half the month's growth in the Domain Validated sector, giving Go Daddy 43 percent of DV Certificates market share.

"More and more people are using Go Daddy for SSL Certs because we offer the industry standard at a fraction of the cost ... and we service each certificate with our personalized 24/7 customer support," said Go Daddy CEO Warren Adelman.

Large and small companies alike can secure their websites at Go Daddy. The vetting process is the same regardless of who issues the SSL certificate. Plus, Go Daddy SSL Certificates have an unlimited server license, meaning users only pay "per domain," not "per server" like others.

SSL certificates provide Web site security through server-to-browser encryption and keep company information, customer data and financial transactions secure. The visual reassurance customers and employers see with an SSL certificate - "https" prefix, a green address bar and padlock icon -- tells users they are working with a legitimate company and their information is safe.

Go Daddy is the largest hosting provider of secure Web sites in the world and the largest host of SSL enabled sites.

source:marketwatch

Monday, 6 February 2012

SSL Certificate, TLS and HTTPS basics


SSL Certificates /TLS provide encryption and authentication for HTTPS.
For maximum security
  • Ensure SSLv2 is disabled
  • Generate private keys for certificates yourself, do not let your CA do it
  • Use an appropriate key length (usually 2048 bit in 2011)
  • If possible, disable client-initiated renegotiation
  • Consider to manually limit/set cipher suites
Rationale
The CA has no need-to-know for your private key. Depending on the cipher suite used, the private key can allow adversaries to decrypt passively eavesdropped communications. Thus, even if you trust the CA, it is better to avoid any risk. Generate a key and a CSR Key and provide only the CSR to the CA.
Increasing key length increases security, but also significantly increases the CPU load for connection establishment. 1024 bit keys will not be accepted by Mozilla Firefox anymore for certificates that expire after the year 2013. 2048 bit keys should be enough for all applications for quite a few years – using larger key sizes seems to be overkill. (All information based on 2011.) Note: The large CPU overhead of connection establishment can be used by (D)DoS attackers. Such DDoS attacks are harder to detect and defend against when client-initiated renegotiation is supported.

SSL Certificates /TLS supports a large set of “cipher suites”, each defining a set of cryptographic mechanisms used to secure the connection. Some of them do provide perfect forward secrecy, some do not. (Perfect forward secrecy means that if the private key becomes available to an attacker, he cannot decrypt data that was eavesdropped before he got the key). Usually, the client (browser) and server choose a cipher suite by first exchanging which suites are mutually supported, and the client’s preferred suite is then chosen. Depending on setup, the server may choose the cipher suite, ignoring the client’s preference. Most defaults are reasonably sane, but for either high-speed or high-security applications, you may want to consider restricting the supported/preferred suites to fast or high-security suites. If you want to exclude clients that do not support sufficient security (e.g. ancient “export control” limited clients), make sure to disable those cipher suites. When configuring cipher suites, carefully check the setup to make sure you do not allow “ADH” suites that do not authenticate the server! If you are unsure, keep the default, and always verify the effects of your settings!

Sunday, 25 December 2011

Web Security Awareness Inspired

As a frequent traveller, going online has become universal for me. I expect Internet access wherever I am for whatever I need. However, when I am on the road, accessing the Internet can be challenging. Connections may be not only slower but also at greater risk, especially when connecting to public networks or using a public computer in the hotel. The key to using the Internet securely while travelling is to understand these additional risks, use caution, and be prepared.

PLANNING AHEAD
One of the most effective ways you can protect yourself when travelling is to first take simple, preventive steps before you leave. If you are using a corporate image notebook, most of the following tasks are likely maintained by your IT desktop management, but nevertheless worth to check frequently by your own, in particular if this is your own device that is not managed by IT.
  • Ensure your laptop and smartphone operating systems and applications have the latest version reduce their vulnerability to attack (i.e. use “Windows Update” in your program list to check).
  • Make sure the firewall on your laptop is enabled. This helps prevent others from connecting to your laptop over the network. Check that your anti-virus software is up-to-date and in good working order (i.e. for both firewall and antivirus check the status icon in the taskbar).
  • Laptops and smartphones are targets for thieves and easy to lose - as we all know and always tell our customers. Enable automatic screenlock on your laptop and smartphone using a strong password or, at the very least, a PIN code.
  • If your laptop or smartphone has personal or confidential information stored on it, consider encrypting the information or your entire hard drive. Many organisations already deploy file- and/or whole disk encryption as part of their corporate images. If you are using your own device, consider software for file encryption and/or for whole disk encryption.
  • If you set an out-of-the-office message, identify a colleague as an alternate point of contact while you are gone. In addition, do not provide specific details about your trip. If possible, limit delivery of your out-of-the-office message to recipients within your organisation or to people already in your address book.
  • Make yourself familiar with the travel safety program of your organisation to see what special services it offers to us whilst travelling.
CONNECTING TO PUBLIC NETWORKS

Always keep in mind that in a public network anyone has access, and your online activities can be monitored by others. In addition, malicious individuals may operate fake Wi-Fi networks that are designed to fool you into using them and potentially attack your system.

When possible, use a sponsored Wi-Fi network hosted by a legitimate organisation. Look for signs with the name of the Wi-Fi network displayed in the hotel lobby, airport terminal, or café. Using these sponsored networks is a better security bet than picking a public Wi-Fi network at random. In addition, when possible use encrypted Wi-Fi networks, and pay attention to the type of encryption. In order from best to worst, the common Wi-Fi encryption types are: WPA2, WPA, and WEP. Even with Wi-Fi encryption, your communications could still be intercepted by other users of the same Wi-Fi network

source:symantec
.
Take the additional precaution of using an encrypted data connection such as HTTPS or Virtual Private Network (VPN). An HTTPS browser session, usually indicated by the familiar padlock icon, encrypts the information you send over the Web. Many websites and online services allow you force that HTTPS encryption be used at all times.

If your organisation provides VPN access, always try to establish a VPN connection via the VPN client into the network of your organisation. A VPN connection ensures that all your online activities are encrypted and unreadable for those that are intercepting your communication.

Another option is to use your smartphone as a Wi-Fi access point – if you have data flat rate and if you are not roaming outside of your home mobile carrier country. If you have a smartphone, contact your service provider about using its +3G capabilities to set up a secure “tethered connection” or “personal Wi-Fi hotspot” for your laptop. In addition, your smartphone’s email and browser capabilities may be enough to meet your needs while on the road. If so, the security afforded by your smartphone’s mobile broadband connection is a better bet than public Wi-Fi.

AVOID USING PUBLIC COMPUTERS

There is no way for you to know who used a public computer before you. It may have been infected or otherwise compromised accidentally, or malware may have been planted on it deliberately. Any information you enter may be stolen by cybercriminals.

Limit your use of public computers to casual web browsing only, such as checking the weather, the status of your flight, or catching up on the news. If you have no choice but to use a public computer to make a transaction or to communicate sensitive information, you have to assume that any information and your login and password you used have been compromised. Keep track of the accounts you had to access and change your passwords immediately the next time you have access to a trusted computer and network.

I hope you find this information useful. If you want to learn more about how to establish a security awareness program within your organisation, please visit the Symantec Security Awareness Program website. This program helps you to train your employees to understand information security issues and behave in a manner that minimizes risks.


source:symantec

Monday, 19 December 2011

Fake Offers For Mobile Airtime Haunts Indian Users

Symantec is familiar with phishing sites which promote fake offers for mobile airtime. In December, 2011, the phishing sites which utilized these fake offers as bait have returned. The phishing sites were hosted with free web hosting.
When end users enter the phishing site, they receive a pop up message stating they can obtain a free recharge of Rs. 100:

Upon closing the pop up message, users would arrive at a phishing page which spoofs the Facebook login page. The contents of the page would be altered to make it look as though the social networking site was giving away free mobile airtime. A list of 12 popular mobile phone services from India would be displayed with their brand logos. Once the page completes loading, the theme songs for each of these mobile services play, one after the other.
This phishing page gives a long (fake) offer description. In the description, users are required to enter their login credentials to receive the free airtime offer. The description further states with pride that the site is the first ever to provide this offer and reminds it is always free for users. In reality, if users enter their credentials the phishing page will redirect to a legitimate web retailer selling online purchases of mobile airtime. The strategy behind bothering to redirect to such a site is to mislead users into believing that a valid login has taken place and avoid suspicion. If users do fall victim to these phishing sites, phishers will have successfully stolen their information for identity theft purposes.
Users should be careful. In the fake login below (in blue and purple text) you can see the claims of free airtime:

The URLs on the phishing page also contained text in them to further lead users to believe this social networking website has a relationship with online mobile airtime recharging. The examples:
hxxp://www.******.******.com/Facebook-rc/facebook2011.html  [Domain name removed]
hxxp://free-r3charg3.******.cc/facebook2011.html  [Domain name removed]
hxxp://free-rechargess.******.cc/recharge/1/3.php  [Domain name removed]
Here are a few best practices for Facebook users to combat these threats:
  • Use unique logins and passwords for each of the websites you use.
  • Check to see that you're logging in from a legitimate Facebook page with the facebook.com domain.
  • Be cautious of any message, post or link you find on Facebook that looks suspicious or requires an additional login.
  • Do not click on suspicious links in email messages.
  • Avoid providing any personal information when answering an email.
  • Never enter personal information in a pop-up page or screen.
  • Become a fan of the Facebook Security Page for more updates on new threats as well as helpful information on how to protect yourself online.
  • Frequently update your security software (such as Norton Internet Security 2012) which protects you from online phishing.
Secure your Facebook Apps by Facebook Apps SSL


source:symantec