- +
Adobe launches hosted services, adds Flash to Acrobat 03 June, 2008 09:02:44
Adobe to launch Web site offering users free hosted services for document creation, sharing and storageAdobe this week is set to unveil the next version of its Adobe Acrobat software, which adds support for the company's Flash multimedia technology. The company also plans to launch a new Web site offering users free hosted services for document creation, sharing and storage. - +
10 things we hate about laptops 16 November, 2007 12:40:09
Sure, laptops have revolutionized the way we compute. That doesn't mean they don't drive IT bonkers.Damaged. Lost. Stolen. Too big, too small. Insecure and unreliable. And just plain annoying. If you're in IT, there's just not much to like about laptops.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Radicati Market Quadrant 2008 on Corporate Web Security
Email Archiving 101—Customer Case Study
Strategies for Eliminating .PST Files
Revolutionising Back-up and Recovery
Why Security SaaS Makes Sense Today
Web Security SaaS: The Next Generation of Web Security
Solve Exchange Mailbox Storage Issues Once and for All
Optimized Back-up and Recovery for VMWare for VMWare Infrastructure with EMC Avamar
Newsletter Subscription
You can wirelessly sync your mobile phone with your laptop. You can use the mobile phone's built-in modem to put your laptop on the Internet. With speed. Without cables. But be aware, even with security built in from the get-go, Bluetooth has problems.
If the wireless revolution has taught us anything, perhaps the single most important lesson is that people who design radio systems are notoriously bad at designing systems that are secure.
Remember analogue mobile phones back in the 1980s and 90s? Those phones transmitted their mobile serial numbers (MSNs) without the use of encryption or even a simple challenge-response system, making it easy for bad guys to clone phones and run up literally billions of dollars in fraudulent mobile phone charges.
We've faced different but equally troubling security problems with cordless telephones, Wi-Fi wireless networking and radio frequency identification (RFID) systems, of course. But we've also seen security problems with relatively simple wireless systems like garage door openers and car alarms. In fact, I can't think of a single wireless communications system that hasn't had a significant security problem. Even worse, the problems have almost always been predicted in advance, pooh-poohed by vendors and then acknowledged to be problems after the equipment is widely deployed.
The very nature of wireless communications systems encourages sloppy security thinking on the part of wireless designers. After all, when a new wireless system is under development and not being sold to the general public, the bad guys - by definition - don't have the wireless system either. As a result, designers are lulled into thinking that many possible attacks would be hard, if not impossible, for a typical bad guy to perpetrate. After all, it's hard to build a new wireless system.
But once a system is built and deployed, the bad guys can examine it. They can also purchase one radio and use it to attack a second. Of course, the more radios that are deployed, the more valuable the attack. Perversely, the more radios that are deployed, the bigger the incentive for the manufacturer to cover up or minimize the impact of the vulnerability - after all, vulnerabilities are potential liabilities.
All of this, of course, brings us to the subject of Bluetooth, the two-way wireless communications system designed to create "personal area networks" between your mobile phone, your mobile phone's wireless headset, your laptop, PDA and whatever other devices you're packing.
Bluetooth uses the same part of the radio spectrum as Wi-Fi wireless LANs. But whereas Wi-Fi uses a technique known as "direct sequence" to encode information, Bluetooth uses a different spread spectrum technique known as "frequency hopping". The Bluetooth transmitter hops 1600 times every second to a different frequency inside unlicensed 2.4GHz radio band. Bluetooth and Wi-Fi are not compatible: If a Wi-Fi system is transmitting a packet when Bluetooth steps through, that packet is lost. For this reason, some businesses have banned the use of Bluetooth on their property for fear of interference with their wireless networks. In practice, though, it's very hard to ban something that's running in a mobile phone unless you physically search everybody entering your property and confiscate the phones of visitors. I've worked at places where such precautions are taken, but for most businesses this is probably a losing battle.
Unlike Wi-Fi, Bluetooth was designed for extremely short-range communications. Class 1 Bluetooth devices have a maximum power output of 100mW and a theoretical range of 100 metres in free space. Class 2 devices have a maximum power of 2.5mW and a corresponding range of 10 metres. Class 3 devices have a power of 1mW and a range of 1m metre or less. Naturally, Bluetooth headsets tend to be Class 3 devices: Using less power, they can have correspondingly longer battery life.
Although it was slow to catch on at first, Bluetooth is becoming increasingly popular. It's built into many PalmOne Tungsten PDAs, available on all Macintosh laptops, many ThinkPads and an increasing number of mobile phones - especially GSM mobile phones sold here and in Europe. With Bluetooth, you can wirelessly sync your mobile phone with your laptop, or use the mobile phone's built-in modem to put your laptop on the Internet. Wireless means no cables to buy, tangle or lose. It's also faster to sync over Bluetooth than over a serial or USB cable. Bluetooth is just cool.
But Bluetooth has many security problems - with more still being discovered.
To be fair, Bluetooth's designers did build a rudimentary security model into the system. For starters, every Bluetooth device has a unique serial number called a BD_ADDR. This serial number is set by the factory when the device is manufactured. Every Bluetooth device also has a database of which other devices it trusts. When it first turns on, every Bluetooth device is supposed to trust nothing. But if you choose, you can explicitly "pair" two devices so that they will trust each other. Once two devices are paired, they can exchange encryption keys and use those keys to scramble all information exchanged between the two of them.
The first problem with this security model is the BD_ADDR itself: Just like an Ethernet media access control (MAC) address, it can be changed. As a result, if an attacker is able to observe the radio communications between two devices, the attacker can clone one of those devices' BD_ADDRs and fool the other.
The second problem is the encryption itself. An attacker who clones a BD_ADDR can't steal a prenegotiated encryption key, but in practice few Bluetooth devices actually turn encryption on. There's also some concern regarding the Bluetooth encryption algorithm: Rather than using an industry-standard algorithm like RC4 or AES, the Bluetooth designers invented their own. Although the algorithm hasn't been cracked, I suspect that it's only a matter of time.
The third problem with the security model is that there are many functions that are explicitly allowed between untrusted devices. One of the most common of these is the Bluetooth function of sending and receiving business cards. This is an allowed untrusted operation because, in theory, you can always delete somebody's business card. But an attacker can use this feature to fill up your phone's address book with a thousand different cards. Alternatively, somebody interested in promoting a new nightclub, for instance, might just walk around town with a program that searches out Bluetooth phones and transmits an advertisement to each one in the form of a business card. There's even a program called BlueSpam (download it from www.mulliner.org) that does precisely this: It runs on a PalmOne Tungsten.
Bluetooth promoters were quick to defend these vulnerabilities, arguing that the limited range of the Bluetooth signal makes the system more secure than it might otherwise be. If somebody is close enough to you that he can send you a piece of spam, you're close enough to reach out and wring his neck, the theory goes. Lots of hip singles in Europe keep their Bluetooth phones enabled all the time: Using business cards to flirt.
There are two problems with this spatial locality argument. First, it is possible to attack somebody's Bluetooth phone using an automated hacking tool running on a PDA that's hidden in your pocket. Since humans can't see radio waves, it's impossible to tell who the attack is actually coming from. The second problem is that the range of Bluetooth devices I quoted above assumes that the devices are equipped with a pretty cheap antenna and no amplifier. Using a 500mW amplifier and a 19- decibel antenna mounted on the stock of a sniper's rifle, John Hering, a student in Los Angeles, created the "BlueSniper" Bluetooth rifle. This weapon can lock on to an ordinary Bluetooth device at the distance of a mile.
The biggest security problem with Bluetooth today, however, has nothing to do with the underlying security model. The big problem is that many Bluetooth devices have the same sort of bugs and security vulnerabilities as those that have been haunting Microsoft since it started shipping Internet Explorer in the mid-1990s: Poor programming practices, poor quality assurance and a lack of attention to security have resulted in exploitable buffer overflows and other kinds of attacks.
One set of vulnerabilities that has been discovered allows an attacker to reach into a phone's address book and retrieve or modify information. Another vulnerability leaves the database of trusted devices open to attack. To be fair, some mobile phone vendors have issued "patches" to fix these vulnerabilities. In practice, of course, many phones won't get patched or otherwise upgraded. You can find an excellent list of which phones are vulnerable to which vulnerabilities at www.thebunker.net/security/bluetooth.htm.
The potential dangers of these vulnerabilities are vast. A Bluetooth virus could be passed from phone to phone by people passing each other in the street. After a week, the virus could turn ugly and have everybody's phone dial 000. In Europe, a phone could issue a so-called reverse short message service transaction and actually transfer money from the phone subscriber's bank account to the attacker's.
There are also privacy issues with Bluetooth surrounding the BD_ADDR itself. Because the number usually doesn't change, an attacker with a lot of Bluetooth sensors around the city could use a BD_ADDR to track people's movements. These problems are very similar to the privacy issues raised by RFID.
I like Bluetooth a lot. I like being able to sync my PDA to my laptop without having to take out a cable. I like being able to use my mobile phone as a laptop gateway. I applaud the goal of universal interconnectivity. But Bluetooth vendors have got to take security issues more seriously, or else we're going to see a new generation of attacks on the mobile telephone system that will make the worms we've lived with on the Internet look like child's play.
Shipments of Bluetooth-enabled products have passed 3 million units per week, according to Bluetooth SIG Incorporated, but many of them are mobile phones that are sold in Europe
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Inside Symantec's Security Operations Center 16 October, 2008 07:38:00
For Symantec clients, the Symantec Security Operations Center is the front line in the fight against network attacks. CSO toured the facility for an overview of how the services work, and for a look at some of the latest threats on the internet todayThe inside of the Symantec Security Operations Center looks like a scene out of the movie "War Games," and in many ways, the connection is fitting. The SOC, as it is known by Symantec employees, is in the business of detecting and analyzing network threats. And as malicious activity online gets increasingly more sophisticated, the war against cybercrime is definitely on. - +
Cyber security threats grow in sophistication, subtlety 16 October, 2008 08:26:00
Researchers say malware, botnets, cyber warfare, threats to VoIP and mobile devices, and the "evolving cyber crime economy" are ever-more sophisticated threatsThe annual report from Georgia Tech Information Security Center identifies five evolving cyber security threats, and the news is not good. - +
Tough economic climate can heighten insider threat 16 October, 2008 07:09:00
As companies downsize, they need to keep an eye out for disgruntled employeesWith a faltering economy resulting in increased jobs cuts and corporate belt tightening, security analysts are warning companies to be especially vigilant about protecting their data and networks against disgruntled employees. - +
Anonymous proxy servers: Necessary or evil? 15 October, 2008 07:13:00
Some security experts believe anonymous proxy servers are only necessary if you're up to no good, while others see them as a legitimate tool for research, pen testing and the like. Who's right?If there is truly a gray zone in the struggle between online good and evil, anonymous proxy servers live there. - +
Four security lessons from the World Bank breach 15 October, 2008 07:39:00
The World Bank is making headlines after a disputed report claims hackers managed to access their secure network for over a year. One security pro offers takeaways that everyone can learn from the breachAccording to a report from Fox News, several servers at the World Bank Group, an organization that offers economic assistance to developing countries around the globe, were repeatedly compromised and breached over the course of the last year.
Progress Software Selected for ACORD Standards Framework 16 October, 2008 09:45:00
Tandberg Data lifts RDX® QuikStor™ capacity to 500GB and offers continuous data protection 16 October, 2008 09:23:00
Kroll Ontrack Offers More Complete Data Recovery Solution with SSD And Flash Capabilities 16 October, 2008 09:00:00
Infohrm Launches 4G SaaS-based Workforce Planning, Reporting, and Analytic Solution 16 October, 2008 08:04:00
Polaris Installs Massive Generators 15 October, 2008 11:30:00
|
||
|
||
|
|
||
|
Strategies for Eliminating .PST Files
Join industry expert Martin Tuip to discover best practice strategy for the archival and removal of .PST files using email archiving. Learn how to ensure long-term email records are there when needed, and reduce the risk to your business and clients.















