April 13, 2024

DOUG.   Honeypots, patches and the passing of an icon.

All that and extra on the Bare Safety podcast.

[MUSICAL MODEM]

Welcome to the podcast, everyone.

I’m Doug Aamoth; he’s Paul Ducklin.

Paul, how do you do?


DUCK.   Very effectively, Douglas.

Welcome again out of your trip!


DOUG.   It’s good to be again… I do have a bit shock for you.

We begin the present with the This Week in Tech Historical past phase, and a few weeks there are such a lot of potential subjects to select from (just a bit peek behind the scenes for everybody) that now we have to commute and resolve which one we’re going to decide on.

So I took the freedom of constructing a Subject Wheel that we will spin, and no matter matter it lands on…

…that’s the subject we focus on.

On the wheel this week, now we have a ton of subjects.

We’ve obtained the primary laptop conference, the Altar Conference in 1976; we’ve obtained the Melissa virus from 1999; we’ve obtained the primary lengthy distance cellphone name in 1884; the invention of the phototransistor in 1950; the disclosing of the UNIVAC in 1951; the primary metropolis to go to full electrical lighting in 1880; and Microsoft Bob in 1995.

So I’m simply going to present the wheel a spin, and wherever it lands – that’s the subject.

[SPINS WHEEL]

[FX: Click-click-click-click]


DUCK.   That is Wheel of Fortune stuff, is it?


DOUG.   Sure.

Wheel is spinning…

[FX: Click-click-click (gradually slowing down)]


DUCK.   I do know the place I would like it to cease, Doug!


DOUG.   And it has landed on [EXCITED] the Melissa virus!

[FX: Dramatic chord]

It’s proper in our wheelhouse….


DUCK.   I used to be secretly hoping for Microsoft Bob.

As a result of now we have spoken about it earlier than, and it was an amazing alternative for me to have a really slight rant/criticism, and to introduce Clippy.

However I can’t point out both of these once more, Doug.


DOUG.   Alright, effectively, the wheel has spoken.

This week, in 1999, the world felt the wrath of the Melissa virus, a mass-mailing macro virus concentrating on Microsoft Phrase and Outlook customers.

The message emailed itself, together with a poisoned Phrase doc, to the primary 50 folks within the sufferer’s Outlook contact record, whereas on the similar time disabling protecting options of each applications.

The Melissa virus was finally related to David L. Smith of New Jersey, who spent 20 months in federal jail and paid a $5,000 effective.

And Paul, you have been there, man.


DUCK.   [SIGHS] Oh, expensive, sure.

This wasn’t the primary mailing malware – we’ve already spoken about CHRISTMAS EXEC haven’t we, which was 10 years earlier than that, on IBM mainframes.

The CHRISTMA EXEC community worm – 35 years and counting!

However this was an indication that now we have been all related, and a variety of us have been utilizing Microsoft Phrase with its macro programming language, and we have been relying closely on e-mail…

…issues might go a bit pear-shaped if there was a virus.

The issue was it wasn’t 50 folks, it was the primary 50 *addresses*.

Most individuals ,someplace shortly after Aamoth, Doug and Aardvark, Christopher had any individual referred to as, for instance, All Customers, or one thing to that impact.

[LAUGHTER]

So, sure, it was a fully large factor.

It had a Bart Simpson reference, didn’t it?


DOUG.   Sure… KWYJIBO. [FAKE SCRABBLE WORD ONCE USED BY BART SIMPSON]


DUCK.   Often it will really stick that right into a doc, wouldn’t it?

David Smith fell foul of the legislation as a result of he fairly merely ought to have predicted the extent of disruption that it brought on.

So, as you say, 20 months in federal jail, and the start of a dramatic period of mass-mailing malware.


DOUG.   Alright, let’s transfer from macros to Moore.

Relaxation in peace, Gordon Moore, 94 years younger, Paul.

In Memoriam – Gordon Moore, who put the extra in “Moore’s Legislation”


DUCK.   Sure.

I had a wierd dialog over the weekend after I ran into somebody over espresso they usually stated, “Oh, what have you ever been doing on the weekend to this point?”

I stated, “Truly, I’ve simply been at work; I used to be writing an RIP, an In Memoriam piece for a really, very well-known particular person within the IT business. Gordon Moore has died at 94.”

And this particular person checked out me and stated, “Oh, I’ve by no means heard of him.”


DOUG.   [LOUD GASP OF DISBELIEF]


DUCK.   And I stated, “However you’ve heard of Moore’s Legislation?”

“Oh, sure, in fact. Moore’s Legislation, I find out about that.”

And I stated, “Properly, similar Moore.”

And so I hope they rushed off to learn the article!

I republished the graphs that he put in his authentic little piece that led to Moore’s Legislation.

That was earlier than he based Intel, really.


DOUG.   Sure, he was a lot… extra, when you catch my drift.


DUCK.   [NOT QUITE AS AMUSED AS DOUG HOPED] Sure.

It’s an interesting little paper.

It was revealed in… primarily in a preferred journal as a brief piece – just some pages in Electronics journal in 1965.

It was nearly jocular in that he was saying, “You understand what we’ve seen at Fairchild?” [COMPANY CO-FOUNDED BY MOORE BEFORE INTEL]

In 1962-63-64-65, when you take the variety of transistors on the chips that we’re constructing every time (the chips are roughly the identical dimension), and you are taking the logarithm base 2 of the variety of transistors, and also you draw a graph, you get a straight line.

Which suggests exponential development.

In different phrases, you may’t simply maintain making the chips greater and larger and larger as a result of they begin failing…

..it’s a must to learn to change the manufacturing course of as effectively, so you may mainly get extra transistors in there.

And the paper known as Cramming extra Parts onto Built-in Circuits. [LAUGHTER]

Actually cramming extra in.

And also you see that, by 1975, 10 years into the longer term, it will counsel that you just may need single circuits that might have as many as 65,000 (or 216) transistors on them, Douglas.

Unbelievable.

That was his concept about how we would innovate.

It didn’t fairly work out like that… by 1975, he stated, “It doesn’t appear to be the doubling yearly goes to proceed, but it surely may very well be roughly doubling each two years.”

And regardless that we haven’t fairly doubled each two years, we’re not far off.

As a result of when you go from 1978, when the 8086 got here out, that had about 215 transistors on it.

And 22 doublings (44 years) later, the Apple M2 chip got here out, so that ought to have roughly 237 transistors on it, which is effectively over 100 billion.

Isn’t that inconceivable?

Not far off: 20 billion transistors on an Apple M2 chip.

Amazingly prescient, Doug.


DOUG.   Certainly.

Alright. The Home windows 10 Snip & Sketch app has been patched, and the Home windows 11 Snipping Device has been patched.

Microsoft assigns CVE to Snipping Device bug, pushes patch to Retailer


DUCK.   Simply to revisit, in case you missed this story, this began with a bug within the Google Pixel photograph cropping software.

You might crop a picture (a photograph or a screenshot that you just already had on the cellphone), and simply hit [Save] over the unique, and also you’d get the model new file…

…adopted by the leftover content material from the earlier picture.

Which you wouldn’t discover whenever you loaded the picture again, as a result of inside the information that was written again over the outdated file is a marker that claims, “You may cease right here.”

So a tester who cropped a file and loaded it again would discover that it appeared right, but it surely probably had left-over cropped information.

So it’s precisely the bug you don’t need, isn’t it?

Google Pixel telephones had a severe information leakage bug – right here’s what to do!

And, in fact, the bug was nothing particular to Google, or Pixel telephones, or Android programming, or Java run-time libraries.

It seems that some Home windows picture and screenshot cropping instruments had precisely the identical bug, albeit for various causes.

What we don’t know, Doug, is what number of *different* apps of this type (they might not be picture editors; they is perhaps video editors or audio editors, or no matter) have the same form of downside.

If you happen to go to Microsoft Retailer and also you go and replace your Snipping Device, you’ll get a model that not behaves this manner.

And in case you have Home windows 10, what’s it referred to as there, Doug?


DOUG.   Snip & Sketch.

I’m glad to report I do use the Snipping Device on a regular basis, and I’m glad to report that mine has been up to date.

I didn’t do it manually, so it both obtained rolled right into a earlier replace or was up to date mechanically.

Nevertheless it’s at all times good to test.


DUCK.   Sure, we put a hyperlink to Microsoft’s article about it, together with the brand new model numbers to search for, within the Bare Safety article.

As a result of, Doug, I didn’t fairly agree with Microsoft’s evaluation of this.

I don’t know what you thought…

They stated it was a low severity bug as a result of, and I’m quoting, “Profitable exploitation requires unusual person interplay and several other components outdoors of an attacker’s management”.

And the issue to me with that assertion is that this isn’t about somebody attacking you or making an attempt to trick you into revealing a picture that you just didn’t intend to.

The issue is that you just’re modifying the picture particularly to take away one thing that you just don’t need in there, and the information that you just visibly had eliminated *didn’t get eliminated*.


DOUG.   Talking of eradicating issues, now we have one thing referred to as [GRUFF VOICE] Operation PowerOFF.

Is it honest to name this a DDoS honeypot?

Cops use pretend DDoS providers to take purpose at wannabe cybercriminals


DUCK.   I feel it’s, Doug.

It’s a multinational factor – so far as I do know, at the very least the FBI, the Dutch police, the German Bundeskriminalamt, and the UK’s Nationwide Crime Company are concerned on this.

So far as I do know, he concept is to try to present what you would possibly name “excessive strain discouragement” to children who assume it will be cool to hang around on the fringes of cybercrime. [LAUGHTER]

It appears fairly effectively established that various children who wish to dip their toes within the water of working on the Darkish Facet are likely to get drawn in the direction of what are referred to as DDoS (or booter, or stresser) providers.

And these are pay-as-you-go providers run by different crooks, the place you may primarily take vengeance on somebody’s web site.

You don’t fling malware at it; you don’t try to hack into it; you don’t try to steal information.

So it sort of feels like a really low degree of criminality: “I’m simply paying to have a complete load of random computer systems all over the world gang up on a web site, ask for the homepage all on the similar time and it gained’t have the ability to cope. And that’ll train them.”

And so, as you say, what Operation PowerOFF was about… was primarily a honeypot.

“Hey, are you curious about entering into booting and stressing? Are you toying on the fringes of cybercrime? Enroll right here!”

And naturally, you weren’t signing up with cybercrooks; you have been really signing up with the cops.

And after a short while, when sufficient folks have signed up, then the location all of the sudden goes lifeless and then you definitely get contacted…

…and also you get to have, how can I put it, a “particular dialogue” [LAUGHTER], which I feel is supposed to dissuade you from doing this.

As humorous because it might sound to you, neither the proprietor of the location, nor the police, nor the magistrates are going to seek out it amusing when you get hauled into court docket, as a result of it does have an effect on folks’s companies and their livelihoods.

And the opposite factor that the cops say that they’re eager to do is basically stitching some form of discord among the many cybercrime group.

If you join considered one of these darkish net providers, how are you aware whether or not you’re signing up with fellow criminals, or with undercover cops?


DOUG.   That is the hazard of when folks hear about botnets or zombie networks…

…perhaps an outdated laptop I’ve that’s unpatched, that’s turned on in my closet or no matter and I’m probably not taking note of.

If it may be leveraged right into a bot community or a zombie community, it may be used for issues like this.

Though I don’t imply to, and I don’t wish to take any web site down, if I’ve an contaminated laptop, it may be used for stuff like this.


DUCK.   Completely.

That’s why, when you’re nonetheless operating XP, when you haven’t patched your own home router for 3 years…

…you’re a part of the issue, not the answer.

As a result of your laptop or your router may very well be used on this method.


DOUG.   With reference to time-wasting, lest you assume penetration testing is a waste of time, we’ve obtained a penetration testing win for e-commerce big WooCommerce.

WooCommerce Funds plugin for WordPress has an admin-level gap – patch now!


DUCK.   Sure – thankfully, that’s the way in which spherical it labored.

They haven’t disclosed any actual particulars concerning the bug, for apparent causes, as a result of then anybody who hasn’t patched… you’d be making a gift of the key for folks to leap in.

It feels like an unauthenticated distant code execution the place you can set off some PHP script, and whilst you have been about it, you can seize admin privileges on the location.

Now, if somebody’s breaking into your WordPress web site they usually would possibly then all of the sudden begin placing up bogus hyperlinks or printing pretend information, that’s unhealthy sufficient.

However when the WordPress web site you’re speaking about is the truth is one which offers with on-line funds, which is what WooCommerce is all about, then it will get very severe certainly!

As you say, thankfully this was disclosed responsibly, and it was patched.

WordPress and the Automattic staff (the individuals who run WordPress) have been knowledgeable, and for most individuals, patches have been pushed out mechanically.

Nevertheless it’s actually essential, when you run a WooCommerce web site, that you just go and be sure you’re updated.

As a result of when you aren’t, there’s a risk that crooks might come on the lookout for this backdoor gap that enables them to get admin entry.

And, in fact, as soon as they’re in, they will get all kinds of stuff, together with hashed login passwords, and what are often called API keys or authentication tokens.

In different phrases, these magic strings of characters that you may put in future net requests that permit you to work together with the location as when you have been pre-authorised.


DOUG.   And the way will we really feel concerning the verbiage?

These passwords have been salted and hashed, so “it’s unlikely that your password was compromised”.

How does that make the hair on the again of your neck?

Is it standing up or is it nonetheless mendacity down?


DUCK.   You set it extra dramatically than I used to be keen to do in print within the article, Doug… [LAUGHTER]

…however I feel you’ve hit the nail on the top.


DOUG.   Sure, I’m going to vary my password simply in case.


DUCK.   Sure, they form of stated, “Properly, the passwords have been hashed.”

They didn’t say precisely how, they usually didn’t give any particulars of how onerous it is perhaps to crack them by making an attempt an enormous dictionary in opposition to them.

And so they stated, “So that you in all probability don’t want to vary your password.”

Absolutely it is a superb purpose to vary your password?

The concept of hashing passwords is that if they get stolen, the truth that the hashes do want cracking first, and that may take days, weeks or months and even years…

…it provides everyone time to go and alter their passwords.

So I might have thought they’d simply say, “Go and alter your password.”

In actual fact, I used to be nearly anticipating to see these bizarre phrases “out of an abundance of warning”, Doug!


DOUG.   Sure, precisely. [LAUGHTER]


DUCK.   So I don’t agree with that.

I feel that is *precisely* the form of purpose why you’ll go and alter your password.

And, as you could have stated many instances, in case you have a password supervisor and also you solely have to vary one password, it actually must be fairly a fast course of.

The one factor WooCommerce did say, and this you completely should do, is that this: you do have to go and invalidate all these so referred to as API keys.

You could do away with these and regenerate them for all of the software program that you just use that interacts together with your WooCommerce accounts.

And WooCommerce have recommendation on how to try this; we’ve put the hyperlink within the Bare Safety article.


DOUG.   OK.

And final, however actually not least… I get nice pleasure out of whenever you do that in a headline; you simply say “Apple patches all the things”, and also you imply all the things.

This features a zero-day repair for iOS 15 customers, as effectively.

Apple patches all the things, together with a zero-day repair for iOS 15 customers


DUCK.   Sure, that was the curious a part of it.

There are fixes for the three supported variations of macOS: Large Sur, Monterey, and Ventura.

There are patches for tvOS and for watchOS.

There’s even a patch, Doug, for the Apple Studio Show…


DOUG.   [LAUGHING] In fact!


DUCK.   …which is a cool, groovy display screen, as a result of it’s not only a display screen, it’s obtained a webcam and all types of stuff in there.

You must plug the display screen in with the intention to apply the patch.

It mainly downloads the firmware into your display screen.

The bug within the firmware on the display screen might permit a criminal to succeed in into the working system in your Mac and really get kernel degree code execution entry.


DOUG.   Oooh, that’s unhealthy.


DUCK.   That’s fairly bizarre, isn’t it? [LAUGHS]

However the outlier, or the super-important replace, was for iOS 15.

These of you could have older iPhones and iPads: their updates embody a WebKit zero-day, a distant code execution assault that some crooks, someplace, are already exploiting.

So when you’ve obtained an older iPhone and also you’re operating iOS 15, completely it’s “Don’t delay/Do it in the present day”.

However I might advocate that for something you’ve obtained that has the Apple emblem on it.

As a result of, whenever you take a look at the vary of bugs that they’ve (thankfully) proactively fastened, they do cowl a variety of sins.

So that they embody issues like (as we stated with the show) kernel degree distant code execution; information stealing; the power to ship a boobyptrapped Bluetooth packet that then lets the attacker snoop in your different Bluetooth information; the power to bypass Apple obtain quarantine checks; and an intriguing bug that simply says “Unauthorized entry to your Hidden Images album”.

I’ve not used the Hidden Images album, however I think about they’re the photographs that you just want to maintain, however you positively don’t need anybody else to see!


DOUG.   [IRONIC] Most likely, sure. [LAUGHTER]


DUCK.   The trace’s within the identify, Doug. [LAUGHTER]

And in addition a bug regarding luring you to a booby-trapped web site, after which your searching habits is perhaps tracked on-line.

So, numerous good causes to use the patches.


DOUG.   Alright, and we’ve obtained a really highly effective but succinct remark, because it’s time to listen to from considered one of our readers on the Bare Safety podcast.

And at first I used to be very tickled by this remark, however then I obtained to pondering, “When you have a bunch of various Apple gadgets; when you’re an Apple particular person… it’s really onerous to trace all these bugs.”

Paul, you do an excellent job of simply getting them multi functional place for folks to see.

And on this Apple article, Bare Safety reader Bart feedback, and I quote: “Thanks.”


DUCK.   I want to consider that remark figuratively, if not actually, as being two phrases, as a result of it’s “Thanks. Excalamtion mark.”


DOUG.   [LAUGHS] I did depart that out of the quote…


DUCK.   As you say, all of it will get a bit bitty on Apple’s web site, since you click on on one hyperlink and also you assume, “Oh, golly, I ponder what’s the essential stuff right here?”

So the explanation for writing them up on Bare Safety is to try to distill that data, of which there’s pages and pages and pages, into an inventory of hyperlinks multi functional place that really provides you the model quantity you want after you’ve achieved the replace (so you may confirm that you just’ve obtained it) *and* one thing that tells you, “Listed below are the actually, actually essential issues; listed here are the bugs that the crooks are already exploiting; these are the bugs that the crooks might have discovered, however thankfully, when you patch, you may get forward.”


DOUG.   Alright, thanks very a lot, Bart, for sending that in.

And in case you have an fascinating story, remark or query or… I suppose, on this case, an interjection you’d wish to submit, we’d like to learn on the podcast.


DUCK.   [DELIGHTED] That’s *precisely* the a part of speech that it’s, isn’t it?


DOUG.   It’s… an interjection!

It exhibits pleasure or emotion. [LAUGHS]


DUCK.   Or each!


DOUG.   Or each. [LAUGHS]

You may e-mail [email protected], you may touch upon considered one of our articles, or hit us up on social: @nakedsecurity.

That’s our present for in the present day; thanks very a lot for listening.

For Paul Ducklin, I’m Doug Aamoth, reminding you till subsequent time to…


BOTH.   Keep safe.

[MUSICAL MODEM]