Tuesday, April 1, 2008

Palm Hires PR Manager Away from Apple

Submitted by Ed Hardy on Sunday, March 30, 2008

The list of high-level Apple employees who have jumped ship to join Palm has a new entry. Lynn Fox, who was formerly the Director of Mac PR, has reportedly been hired by Palm.

There can be little doubt that the man behind this move is Jon Rubinstein, Palm's Chairman and an Apple alumni himself.

Rubinstein has been shaking up Palm's management team since he joined the company around the middle of last year, and Fox isn't the first person he's lured over from his old company.

For example, Mike Bell was brought on board a few months ago to be Palm's Senior Vice President of Product Development. Previously, he was Apple's Vice President, CPU Software, in the Macintosh Hardware Division.

So far the hiring of Fox has not been announced by Palm, but Rubenstein's habit of "poaching" Apple employees has reportedly become a sore subject between the two companies. The only acknowledgment Palm made that it had hired Bell was his name appeared on its list of executives.

Microsoft announces Windows Mobile 6.1, device upgrades

Though it's been circulating through the user community (and a Sony Ericsson lab or two) for a little while now, Windows Mobile 6.1 had never gotten officially official in its own right -- until now. Microsoft has taken the wraps off the latest rendition of its mobile platform at CTIA today, a small step on the path to Windows Mobile 7 that'll provide Microsoft-based smartphones with a breath of fresh air starting later this year. The changes are expectedly minor as 0.1 releases tend to be, offering a new Getting Started Center to ease the process of setting up a new device, home screen tweaks, and -- finally -- true, native threaded SMS.

Additionally, Microsoft has announced that a phalanx of carriers and manufacturers have thrown their support behind upgrading devices that are already in the marketplace, which is exactly what we were hoping to hear. Everything from the Pantech Duo, to the AT&T Tilt, to the Sprint Mogul is getting 6.1 love beginning this quarter of the year -- though exact dates haven't been announced. Follow the break for the full list of devices on the upgrade list or have a peep at our 6.1 gallery over on Engadget Mobile!

Mobile operators:

* Alltel Wireless: HTC PPC6800, HTC Touch
* AT&T: Samsung BlackJack II, MOTO Q 9h global, Pantech duo, AT&T Tilt by HTC
* Sprint: A new Palm Treo and updates for the Mogul by HTC, Touch by HTC, MOTO Q 9c, Samsung ACE
* T-Mobile International: T-Mobile MDA Ameo 16 GB, T-Mobile MDA compact IV


Device-makers:

* ASUS: New phones including the P320, ZX1, P560, M536 and updates for the P527, P750, M930
* HTC: A new Touch Dual for the U.S. and updates for the AT&T Tilt, Touch by HTC, Mogul by HTC from Sprint, TyTN II
* i-mate: 8502, 9502, 8150, 6150
* Intermec: CN3
* Motorola: MOTO Q 9c, MOTO Q 9h global, MC70, MC9000
* Pantech: Pantech duo
* Samsung: BlackJack II
* Toshiba: Portégé G810,Portégé G910

The Cost of Networking @ Blackhat

Posted by Gunter Ollmann on March 29, 2008 at 12:29 PM EDT.

The second day of Blackhat Amsterdam proved to be just as good as the first, with the afternoons presentations generally being of more interest to me than the mornings (my perception may have been unduly tainted by the previous evenings late night meanderings and consumption of fermented liquids with the usual flock of pentesters).

Intercepting Mobile Phone/GSM Traffic

The first talk to stand out to me was “Intercepting Mobile Phone/GSM Traffic” by David Hutton and Steve. The room was pretty full and the back row was consumed by various media with camera’s in tow. Having not heard all the rumors etc. about the talk, I was a little surprised that so many people were interested in GSM interception and breaking A5.1 – after all, the theory and proof points have been around for over a decade now.

They did a great job outlining the historical security flaws concerning GSM, and their observational decodes of current GSM handshaking processes revealed that mobile operators don’t appear to be following their own advice on securing critical data (such as the pain-text IMSI number of the handset).

For the last couple of years I’ve been talking about illegal GSM/GPRS interception, with the primary vectors relying upon active equipment (e.g. cell-boosters, nanocell stations, etc.) and degrade attacks. Their completely passive cracking of GSM calls was very interesting because they are able to do it with only a few data packets and were able to make use of rainbow-tables to accelerate the actual cracking of the A5.1 encryption. So, hats off to these guys.

While the GSM side is very interesting and completely noteworthy, I think that perhaps the most important part of their presentation was actually their use of FPGA boards (Field-programmable gate array) to radically accelerate the generation of their rainbow-tables. For example, using a single high-speed PC it would have taken 33,235 years to generate the table (550,000 A5.1’s per second). Using 68 FPGA boards mounted in a custom chassis they did it in 3 months (at 72,533,333,333 A5.1’s per second).

It’s significant because this is (now) a very public case of how “off-the-shelf” FPGA hardware can be used to boost specialized cracking processes by many orders of magnitude. Given the fact that these processing technologies are relatively cheap (and getting both faster and cheaper), I’d recommend companies take a much closer look at the key lengths of the encryption systems they currently use – and reevaluate the amount of time that attackers will need to crack their systems in the future.
I’d also point out that it’s definitely worth bearing in mind that (in most cases) today’s encrypted traffic can be recorded and then cracked by the attacker at their leisure. So you should factor in how long any data (especially classified communications transmitted over wireless interfaces) will need to remain confidential – and that Moore’s law is way too conservative.

Investigating Individuals and Organizations Using Open Source Intelligence

The other talk I found very interesting (and capped off two days of Blackhat) was titled “Investigating Individuals and Organizations Using Open Source Intelligence”, delivered by Roelof Temmingh and Chris Böhme.

Having come from a penetration testing background, I’ve always relied upon passive information gathering techniques to start the ball rolling for any engagement. Roelof and Chris have managed to take this to the next stage and made it much more personal by automatically linking public information stores (such as that from social networking sites) to extract personal information – effectively paving new ways for effective social engineering and manipulation of Web 2.0 social/collaborative networks.

Granted, there may be some legal gray-areas – such as breaking fair-use and terms-of-use clauses at some social sites – but, at the end of the day, it’s not like the bad guys are actually going adhere to the rules, so it’s important that professional security researchers be allowed to examine these areas (I mention that point because Roelof and Chris managed to get a few ‘Cease and Desist Trespassing’ letters from some well known Web 2.0 sites).

I found the most interesting aspects of their talk to be about the use of imaginary virtual friends and the subsequent creation of entirely fake virtual communities.
For several years the X-Force have monitored the manipulation of search page-rank manipulation of organized cybercrime units. Today, with drive-by-malware and man-in-the-browser attack vectors, page-rank manipulation has fast become one of the most dangerous and insidious attack propagation vectors. With the worldwide news event of Benizar Bhutto’s assassination, the public got the first real taste of how criminals can leverage page-rank manipulation to infect browsers as they search for news and background history on key events (e.g. for a period of time, the first few links returned by popular search engines pointed to malicious hosts serving up exploit code and infecting visitors with botnet agents).

What Roelof and Chris managed to do in their talk was to clearly show how the creation of even “dumb” AI processes can govern an army of completely virtual identities, bypass current generation “is it a real human” tests, and manipulate community ratings (e.g. guarantee that a particular movie will be ranked number one). Which in turn can be used in very profitable ways – e.g. what happens if you’re the movie’s producer? Higher ranking equals more viewers and higher box-office revenues (in fact some people would argue that the precedent has already been set and has been happening for decades with the music industry’s Top-40 listings).

With cyber criminals proving adept at following the money, I have little doubt that somewhere around the world someone is already coding up the first generation of AI virtual identity agents in preparation for distribution to existing botnets.

That's yet another “blade” to existing botnet malware and a low-hanging-fruit vector for making money – governed only by the imagination of the criminals.

Apple Crumble @ Blackhat

Posted by Gunter Ollmann on March 28, 2008 at 7:08 AM EDT.

It's been an interesting day at Blackhat Amsterdam. As conference venues go, you can't really beat having Blackhat in Amsterdam - the city is alive at night (even if you manage to filter out the red hue around certain districts) - meanwhile, at the conference level, the actual number of attendees is pretty small, but the atmosphere is cozy and open to discussion; something not so common at other cookie-cutter security conferences.

The highlight of the day was the presentation given by Stefan Frei and Bernard Tellenback titled “0-day Patch – Exposing Vendors (In)Security Performance” covering their analysis of several years of vulnerability disclosures and patching processes from various vendors, and a detailed dissection of Apple’s and Microsoft’s performance. (from the X-Force perspective, we’ve looked this data in the past, however their analysis focused on correlating multiple external data sources and honing in on the CVE-numbered vulnerabilities with full ‘cradle-to-grave’ disclosure histories)

In essence, with their “0-day Patch” metrics, they managed to show just how far Apple is trailing Microsoft in security patch responsiveness – in fact, after inspecting their graphs, Apple appears to be trending entirely in the wrong direction; more vulnerabilities, longer patching times, more 0-days, etc. – not the sort of thing we expect from a well known software vendor.

While I think that there are quite a few reasons why this is probably so, I’d be inclined to say that Apple’s biggest problem appears to be that they treat every new vulnerability as a potential PR disaster rather than an opportunity to visibly reinforce their work in securing their customers. In recent times this has most critically been reflected in the way Apple works with security researchers (e.g. I’m yet to find a single security researcher that has had any positive things to say about their dealings with Apple’s security team).

While all of todays presentations were good and of a high quality, perhaps the most interesting presentation for me personally today was that of Christopher Tarnovsky - “Security Failures in Secure Devices”.

Diving deeply in to an area of security research and vulnerability discovery that I’ve never been involved with, he covered his work in the field of Integrated Circuit (IC) design. It was great to see and hear of his experiences in hacking IC’s – decapsulating the chip substrate, invasive probing, methods of introducing electrical and optical glitches, and generally bypassing current chip-level protection schemes.

Seeing a master like Chris discussing his work was fantastic (I guess playing with acid, lasers, and high-powered microscopes has it’s attractions too), and I’m sure he made it look much easier than it really is. That said, his work clearly shows that no matter how well you engineer protection (even at the chip-level), if you have unrestricted physical access to the technology you’ll always be able to break it and – in this case – extract the carefully guarded cryptographic keys that lay at the heart of modern access control technologies.

Apple updates Aperture photo software with version 2.1

Apple has released an update to the latest release of its popular RAW conversion and photo editing software, Aperture.

The headline update in version 2.1 is the addition of open plug-in architecture; expect third-party plug-ins for Aperture, including Tiffen's Dfx and PictureCode's Noise Ninja, to begin providing a range of new tools within the software in the near future. To this end, Apple got the plug-in ball rolling, providing a manufacturer-developed dodge and burn tool with Aperture 2.1.

Aperture 2.1 is available for purchase directly from Apple for $199, or as a free update for Aperture 2.0 users.

Adobe unveils free online version of Photoshop

In an announcement late last week, Adobe – maker of the famed Photoshop image editing package – made a version of its headline product available for free to anyone with an internet connection.

Adobe opened the public beta testing phase on its latest Photoshop offering, Adobe Photoshop Express, which provides easy-to-use versions of many of Photoshop's most useful editing functions in a user-friendly, browser-based interface. The free Rich Internet Application (RIA) makes sorting and cataloging images equally easy, providing two gigabytes of free online image storage space and connectivity with social networking sites like Facebook.

Unique functions in Express combine several steps in traditional image editors into single, simple functions that create effects like selective color, sketch, and soft focus. All editing in Express is non-destructive: the original images remain untouched, allowing for infinite levels of undo.

Photoshop Express is now available to test drive. Visit www.photoshop.com/express to check it out.

Government Announces Penguin-Proof Firewall

Tuesday 1st April 2008

Today, government spokesman Uma Head made a startling announcement - that there were too many foreign operating systems in Britain today, and something needed to be done. She declared, "Over the past decade or so, we have seen an unprecedented rise in the choice of operating system, at the cost of our own native operating systems."

Naturally, her comments have drawn both fire and applause. One advocate of the scheme, Lou Smorals, agreed with Uma Head, stating, "The effect of other operating systems on the software industry in the UK has been devastating. Annually, the cost of damage runs into the millions of pounds, and it's about time something was done. These foreign pieces of software erode our own sales, leaving developers vulnerable to unemployment. It could take hundreds of years for the software trade to regenerate."

"History is replete with examples of our own national treasures been lost. RISC OS on the Acorn Archimedes was displaced by its American cousins, and frankly I am no longer willing to tolerate these events."

In the past, Uma Head has suggested various control measures, none of which have been used. This includes releasing a virus into the population that specifically hunts the undesirables. The proposal was rejected on the grounds that, while it might be effective in the short term, operating systems would eventually find defences against the virus and return to previous levels.

Another discarded idea was for the government to build a portfolio of software patents, while denying them to companies. Then, by bringing excessive numbers of cases to foreign companies, they would be trapped between expensive lawsuits and the fear and uncertainty over whether they really do run foul of patents. The concept was abandoned because, in the government's words, "This would mean nationalising software patents, and we never nationalise anything anymore. Well, usually."

When pressed on specific details, Uma Head revealed that there are plans to stop the downloads of foreign Linux distributions, already dubbed the Great Penguin-Proof Firewall of Britain. However, security expert Michael Estral asserted that the measure would have very little impact. "This is another example of government stupidity. Blocking such a specific type of download is very hard - or, to put it another way, this will likely become very simple to circumvent."

Of course, technical difficulties aside, the logic of the move has been questioned by some. Economist Sue Veneer explained, "For a government that supposedly promotes free trade, this scheme is a complete contradiction of what has gone before. This project is bound to cost vast quantities of money for very little benefit, if any."

Government official Bob N. Dukabit rebuked this by saying, "I think you'll find this to be totally in line with past government behaviour. After all, it's liable to cost vast quantities of money for very little benefit, if any." [Shome mishtake, shurely? Ed.]

Others have voiced concerns over the targeting of Linux distributions. One member of the community said, "I wonder why it's just Linux that is being stopped - surely it's easier to prevent sales of operating systems that come in a box? Naturally, I'm sure this has nothing to do with Uma Head's 'special relationship'" - clearly referring to the recent rumours that Uma Head has been involved with a certain senior member of a certain company in Redmond.

Opposition politician Marge Arine has defended the sometimes unpopular alien operating systems, stating, "We really need the public to get out of the mindset that these foreign pieces of software are stealing jobs from our workers. They are, in fact, a huge boon to our economy, and help to keep prices down across markets by being cheaper and more efficient than many native implementations."

Earlier in the year, one junior minister jokingly suggested that that foreign software houses should be destroyed by "ripping, ploughing, blasting and fumigating." This would prove to cause a major embarrassment when civil servants failed to recognise the joke, and, taking the orders seriously, began preparation before being told the minister was just having a giggle.

Uma Head is 46¾.