Monday, 15 March 2021

A Circular Reference:

A friend of a friend told me that they know someone who created a QR code that logged into the QR code generator web-site that they had an account on, so they could save time creating the specially formatted QR codes with the corporate logo, that they placed in all the company publicity and marketing material...  

QR Code for this page
QR Code for this page











(QR codes are just URLs. But as a general rule, anything that stores a 'login' (User ID, Password) is not a good idea, and is a Security Risk. If it gets into the wild (and QR codes are easy to send...) then it would become a Security Threat...

And it you ever wondered what happens if you invert the colours on a QR code... 

(Does this tell you something about how the QR code is encoded / decoded?)


A Poor Reference:

'A friend of a friend told me that they know someone...' is an example of an unreliable InterWeb 'reference' that is either intended as obfuscation (as in this case), humour (perhaps in this case), indirection (maybe the source doesn't want to be revealed), or even seriously (seriously?) as a reference. In almost all cases, this type of phrase contains so many levels of indirection that it isn't really a reference at all.  

But not all poor references are as easy to spot as this one. If you see a reference with a URL, do you check the URL? Would you even pause to check the URL itself before clicking on it? Is this a way of getting normally savvy people who never click on links in e-mails to break their own rules? Is indirection or obfuscation a potential problem because the actual link content is hidden. Surely a shortcut just makes things easier...  And of course, QR codes can sometimes be regarded as more than what they appear because they do have a hidden feature - they are innocuous-looking shortcuts that might bypass safeguards... Luckily, they won't ever be used by phishers, friends of phishers, and friends of friends of phishers*. Never. Ever.

In the wild, have you ever noticed how posters with QR codes often have stickers over the QR code - with another QR code on them. Presumably this is to fix an error in the printing, or an update, or can you think of another reason?

* This statement may not be true.

- - - 

If you find my writing helpful, informative or entertaining, then please consider visiting the following links for my Synthesizerwriter alias (I write several blogs, but it makes sense to only have one 'Coffee' donation link!):


Synthesizerwriter's Store
 (New 'Modular thinking' designs now available!)

Tuesday, 2 February 2021

Visual metaphors for IT security...

In a world where photos on mobile phones are a way of getting people's attention, what are the visual metaphors for IT/cyber security? 

Locks, safes, Matrix-style 'dropping' green characters, and various cyber-punk staples are all very well-worn cliches. One way of surveying what is 'out there' is to look at an online photo resource. Here's an example of what Unsplash.com came up with from a search for 'computer security':

Photo by Cookie the Pom on Unsplash

Well, it got my attention!

All of which got me thinking, and I'm now thinking about gathering some photos that shout 'IT security' or 'Cyber security' more to me! Watch this space...

---

If you find my writing helpful, informative or entertaining, then please consider visiting the following links for my Synthesizerwriter alias (I write several blogs, but it makes sense to only have one 'Coffee' donation link!):


Synthesizerwriter's Store
 (New 'Modular thinking' designs now available!)


Saturday, 10 October 2020

Hardwear.IO Wall Challenges - Q&As and Extras!

 Some post-conference extras for the Wall Challenges...


Thanks to everyone who entered the Wall Challenges!

The concept of giving the answer away right at the start, and then making the challenge explaining 'why' each question led to that answer, seemed to be very popular! We got more than twice the number of entries compared to the previous Wall Challenge. The email inbox was very busy - there were 65 emails from entrants. And the Discord channel was melodious and mellifluous (and not discordant!).

Questions


If you didn't enter, and want to get the same experience, here are just the 'questions':

https://youtu.be/cYKE2tgw-eY

Just pause the video whilst you think...

Answers


And if you want to know the 'whys', then here are the 'answers':

https://youtu.be/RepW5VTb09c

One final thought about the entries: If there had been a prize for 'Most beautifully and clearly laid-out entry', then Loïse from Brightsight would have won... Unfortunately there was only one prize (for the winner), but my congratulations for a very organised answer! 

Resources


Some entrants did more than just explain why the answer is connected to the question, they provided links to online resources that they used as well. Here are a couple of links to explore:

https://gchq.github.io/CyberChef/

CyberChef is a brilliant toolkit for transforming text (and data) in many ways. It makes all sorts of interesting processing quick and easy to carry out, and can save lots of paper and pencil sharpening. The source is a very good indicator of just why Wall Challenges are 'Security Training in Disguise'. 

👍👍👍👍👍  (5 thumbs-up!)

https://www.dcode.fr/en

dCode is another set of excellent tools that can be very useful in manipulating text and data - plus a lot of other miscellaneous operations and functions. 

👍👍👍👍👍  (5 thumbs-up!)

Both of these should definitely be in your toolkit!

Oh, yes, and I can neither confirm nor deny that I may have used some of these online resources (as well as paper, pencil and pen) to create the challenges... 

https://www.rapidtables.com/convert/number/decimal-to-binary.html

Not quite in the same league as the above two examples, but still useful...

👍👍👍  (3 thumbs-up!)

Previously on Wall Challenges...


There are more wall challenges, door quizzes and wall games that I have produced over the years. Caution: many of these are considerably more difficult than the ones above.

2020 HWIO Virtual Conference:       Q            https://youtu.be/M7MWse68EJo

                                                            Q&A     https://youtu.be/_chBxq4P_5Y

2018 Hardwear.io Conference            Q           https://youtu.be/O34eoI9H3bM

                                                            Q&A     https://youtu.be/n_TAkt6uziw

MinamiCon 22                                              https://youtu.be/civb19tgF2k

                                                            Q&A     https://youtu.be/foF3jxud3oE

If you browse through my YouTube channel, then you will find even more challenges... (No prizes!)

Ah!


Yep. There's a deliberate error in the example question shown at the start of this blog post. Can you figure out what it is? There's a clue in the picture...

---

If you find my writing helpful, informative or entertaining, then please consider visiting the following links for my Synthesizerwriter alias (I write several blogs, but it makes sense to only have one 'Coffee' donation link!):


Synthesizerwriter's StoreSynthesizerwriter's Store
 (New 'Modular thinking' designs now available!)




Wednesday, 30 September 2020

Hardwear.IO 2020 Wall Challenges

The Hardwear.IO conference is online on the 1st and 2nd of October 2020, and they used me for some of the pre-publicity! As usual, I've submitted some Wall Challenges for people to try and solve, and here's a visual clue that may or may not help...

My Wall Challenges are a way to get you to look at the world differently. Hardware is an interesting mix of the old, the new, the obscure and the arcane, and often requires you to think in two or more directions at once. 

Here's an example of multi-directional thinking: 

You have hired a pen-tester company to check your latest piece of hardware. The tester starts their analysis by trying to brute-force the hidden RS232 terminal via the pins that you tried to obfuscate by spreading them across the board, not silk-screening them, and making them look like ATE test-points and unpopulated thru-holes. Of course, the tester finds them disarmingly quickly. The User ID is totally obvious, and the password is just 8 numbers. so you are expecting that to be cracked pretty quickly as well. But after a day or so, the tester is not looking happy, and has not gleefully told you the UID and password. What might be happening?

1. One of the developers lied to you and deliberately set a very long password.
2. There's a bug in the terminal login code and it won't actually accept any password!
3. The tester thinks the obvious User ID must be a honey trap, and is trying other routes into your micro-controller.
4. The tester's USB-to-Serial adapter is broken.
5. The tester hacked your hardware in a few minutes, has all of your micro-controller code, and has IDA'd it so he knows just about everything about how it works - but is worrying that it was too easy and doesn't dare tell you!

Actually, the tester's brute force programme was broken and wasn't brute forcing at all... 

Post-conference Wall Challenge Extras: 

https://securitytiruces.blogspot.com/2020/10/hardweario-wall-challenges-q-and-extras.html

---

If you find my writing helpful, informative or entertaining, then please consider visiting the following links for my Synthesizerwriter alias (I write several blogs, but it makes sense to only have one 'Coffee' donation link!):


Synthesizerwriter's StoreSynthesizerwriter's Store
 (New 'Modular thinking' designs now available!)








Wednesday, 27 May 2020

How to edit an old blog post so that it looks like a prediction...

In a world where fake news seems to be a major part of the news, then it is interesting to see just how easy it is to break the trust that people put into 'systems' and their senses. '

For senses, then 'I only trust what I can touch with my own hands, or see with my own eyes' is one example, which counterfeit goods, photoshopped images and 'deep fake' videos show isn't a very reliable way to assess if something is genuine.


For systems, then a time-stamped published blog post seems like it might be a modern digital equivalent of the classic 'Photo of a newspaper fixes the earliest possible date when the photo could have been taken...' scenario. So a blog post, which is stamped with the time and date that it as published, might seem to be a good way of showing when you first published a thought, idea or comment.

Unfortunately, the design of many systems is not perfect, and sometimes it doesn't do what it appears to do. Blog posts, for instance. The time and date that are shown in Google Blogger (which is what I use to publish this blog) are when it was first published. Any changes after that do not change the time or date, because a blog (from 'web log') is meant to be a series of 'diary'-like entries, and you don't generally edit your diary... So the design of a blogging application (or program, as they used to be called!) has a time-stamp for the publishing date as a key requirement, but there's no requirement at all for time-stamping any edits, and in fact, if you did change the time-stamp for each edit, then it would stop being a log. Even worse, suppose that a picture, photo, graphic, web-site, web-page, or an article in the published blog post was replaced or updated (the original disappeared, for instance), then changing the publishing date changes the time and date of the blog even though none of the major part of the text has changed. What happens when a different advert is placed in the blog post?

So, by design, the time-stamping in Google Blogger (and many other blogs) is a useful way to find out when a blog post  was first published. But that is all. Any subsequent edits are probably not reflected in the 'published on' time and date stamp.

A security-minded person looks at this design and sees a flaw. Most people will look at the 'published on' time and date stamp and assume that it means when the blog post was published. The analogy with the time and date printed at the top of a newspaper is firmly locked in many people's minds. Even if edits were time-stamped, then how do you know you can trust the time-stamping process? Winding back the date on a computer so that '30-day' trials of software continue to work is a very old approach - and triggers an interesting 'vulnerability/mitigation' escalation 'ladder' if you try to stop it happening. These things boil down to: "How much time and effort is it worth to you, trying to make this perfect?', because whatever you do to try and secure your time-stamp will probably introduce one or more new possibilities for subverting it, albeit with more required effort. And nothing is perfect!


So, if you look at this blog post, from the 2nd of October 2018, you will see an edit that I made today to a blog post from more than 2 years ago... but the published date and time were not affected. As you can see, it looks like I had a bad feeling about 2020 way back in 2018 - or maybe I didn't and I just edited the blog post. Does this prove anything? Well, it proves this:

Don't trust blog posts - except blog posts that tell you not to trust blog posts!    

So editing is easy! And a little bit of 'thinking ahead' provides an interesting principle: if you publish a blog post a few times every month for a few years, then you can go back at any time in the future and edit it to say anything at all! I'm now wondering what I should predict next...

The Catch!

This wouldn't be a security blog post if there wasn't a 'gotcha'! Yep, whilst Google Blogger (or other blog apps) display the time-stamp for when the post is published, there are ways to find out when it was altered as well. The Internet 'Wayback Machine' grabs web-pages (Only 439 billion or so - not all of them!) and so can be used as a 'view into the past' - but it also allows pretty detailed investigations of when something has been changed. Now hacking the Wayback Machine is a possibility to cover tracks, but...


This is probably a good moment to remind you that useful resources like the Wayback Machine need money, so I encourage you to go to the web-page and donate! I have donated!

---

Whilst you are thinking about donating to the Internet Wayback Machine, then if you also find my writing helpful, informative or entertaining, then please consider visiting the following link for my Synthesizerwriter alias (I write several blogs, but it makes sense to only have one 'Coffee' donation link!):




Friday, 15 May 2020

The considered view is better than the initial reaction...

Some time ago, when lockdown first started, there was a lot of mainstream media coverage about how insecure some videoconferencing apps were. As always happens these days, some security companies may have been tempted to use this as a way to get publicity by releasing reports detailing their investigation into the risks of using those videoconferencing apps, plus some videoconferencing marketing people might have considered using this as an opportunity to promote their product, and all of this was then reported by mainstream media with a variety of biases and hidden agendas, plus the ongoing desire to capture eyeballs and clicks. I've been intrigued for a while by the view that says that 'Fake News' is a new phenomenon, because I have always thought of all news 'information' as being potentially flawed and requiring a critical appraisal. More broadly, the:

'Trust no source, check everything'

approach has always been very useful insurance. One example that I'm familiar with is that some editions of some of the standard text-books on analogue filter design have contained errors in some of the formulas (or formulae). The tricky bit here is 'some', because this means that the usual 

'check in a couple of reference works' 

approach can fail, because they might both contain the same error! Also, in an online world, what counts as a 'reference work' these days? I have always been intrigued by the way that YouTube and other online social media platforms use words like 'authoritative' when describing sources of information - they don't use words like 'legal' or 'experts' or 'scientists' or 'legislators'. Now appearing to be 'authoritative' would seem to be rather subjective to me, whereas acquiring 'expert' status can be objectively assessed, albeit with caveats because the assessment can be flawed. 'Edition n contains errors, whilst edition n+1 fixes previous errors, but may still contain a different set of errors' is one way of looking at it.

When the mainstream media report on security, then there is a spectrum of opinions from security practitioners about how well they do it, ranging from 'They don't understand', through 'Most of this is kind of true, but...' to 'They understand'. My usual reaction is something like: 'They are describing some of the basic levels of this, but many of the important nuances and fine detail are missing, because to simplify a complex subject for a general audience is obviously a challenge.'

On Twitter I said that my first source of news was from inside the security community, and that Bruce Schneier or Brian Krebs (or Matthew Green, but I kept the Tweet short) would be my preferred way to get an initial informed view on any security issue that the mainstream media were talking about. And yes, I'm well aware that it is rare for the mainstream media to talk about security, and that the time delays in publishing specialised blogs and mainstream news are different. And no, the order wasn't meant to be significant!

So here we are some time after lockdown started, and this is probably a good time to look and see what the 'considered' opinions are.

Here's Bruce Schneier giving some thoughts, which refers to an NSA survey and another one from Mozilla, plus another from Matthew Green, and some on a specific app from Brian Krebs ... Many security companies and organisations have published guides on 'Things to Consider' when using a videoconferencing app or 'working at home'. - here are some examples from Kaspersky , ITGovernance , the New Zealand NCSC , and a the UK NCSC  ...

It is very interesting to take the surveys and to compare them to a lot of the mainstream media headlines, articles and some social media 'statements' that appeared in the first days of the lockdown. What you find is, and I'm repeating this deliberately: 'They are describing some of the basic levels of this, but many of the important nuances and fine detail are missing, because to simplify a complex subject for a general audience is obviously a challenge.' For me, it is interesting to see how many of the statements like  'X does end-to-end encryption (or choose your own feature of interest), Y does not.' are not backed up by the surveys - either as 'X and Y do not', or more interestingly and relevantly: 'it isn't as simple as that...'.

So is the considered view better than the initial reaction? I would guardedly say: 'Yes', but that's not a complete and definitive 'yes'. It depends...and that opens up a whole series of interesting things to explore about truth...

---

If you find my writing helpful, informative or entertaining, then please consider visiting the following  link for my Synthesizerwriter alias (I write several blogs, but it makes sense to only have one 'Coffee' donation link!):









Wednesday, 6 May 2020

One day there's going to be an automated security disclosure...

I was just a little surprised when Instagram sent me a message that appeared to 'express an opinion'...


But it set me thinking about how easy it would be for a developer to write an automated message template that leaks confidential information via an unexpected side-channel... Risk assessment of tiny scripts that do apparently innocuous things, anyone?

Names are interesting things. I once tried to get a hi-tech music themed sticker printed by one of the on-line drop-shipping companies and the artwork was rejected because of a copyright strike. I had used the word: 'Device', as in an electronic music device, but this was flagged up because 'Device' was the name of an American industrial metal band in 2012, and so was trademarked...

---

If you find my writing helpful, informative or entertaining, then please consider visiting the following  link for my Synthesizerwriter alias (I write several blogs, but it makes sense to only have one 'Coffee' donation link!):





NULLCON 12, Berlin, April 2022

Here's the badge that I designed for the NULLCON 2022 Berlin security conference (and highly recommended training!).  The NULLCON 2022 b...