Saturday, October 1, 2016

United States set to Hand Over Control of the Internet to ICANN Today


Since the foundation of the Internet, a contract has been handed over to the United States Commerce Department under which the department had given authority to regulate the Internet.

After 47 years, this contract ends tonight at midnight EDT i.e. Saturday, October 1st, 2016.

If you think that the United States owns the Internet, then you're wrong. It doesn't.

Founded in 1998, non-profit organization

ICANN

(The Internet Corporation for Assigned Names and Numbers) oversees the Internet's "address book" (or root zone) — the process of assigning domain names and the underlying IP addresses to keep the Internet running smoothly.

But according to the contract, ICANN works under the supervision of National Telecommunications and Information Administration (NTIA), an agency of the U.S. Department of Commerce.

That contract is ending today, and the US Commerce Department is

scheduled

to hand over its role to ICANN, which will now become an autonomous body, accountable to an international multi-stakeholder community which includes members from the technical community, businesses, telecommunications experts, civil society and governments.

The Internet itself was designed to function without a central authority and has become a critical part of everyone's life, as well as for the global economic infrastructures.

Four States Sue to Stop "Internet GiveAway"

However, this plan is not without a bit of last-minute drama.

It's already a known fact that majority of the political portion of the United States doesn’t want to give way the Internet. In fact, the process of "losing control over the Internet" has already been opposed by some conservative officials and lawmakers.

Four Republican states' attorneys general have

filed a lawsuit

in a last-minute effort to prevent the Obama administration from ceding control of the internet's critical functions to ICANN, though a federal judge has already denied the request.

With ICANN not under US control, the attorneys general for Arizona, Oklahoma, Nevada, and Texas, fear that "authoritarian regimes like Russia, China, and Iran will now have the ability to interfere with what should be a free and open internet."

"The President doesn't have the authority to simply give away America's pioneering role in ensuring that the Internet remains a place where free expression can flourish," Texas attorney general Ken Paxton said [PDF].

But, after the Edward Snowden’s revelations of NSA's worldwide surveillance program, Internet users don't trust the United States, and they want the Internet to be a free and uncensored platform.

Even the

father of the World Wide Web

Sir Tim Berners-Lee wants the Internet to be decentralized in order to eliminate middleman entirely from all aspects of the Web.

However, this transition would not make any significant change for the Internet users because the companies that oversee the top-level domains, including .com, .org, and .net, are based in the United States, meaning they have to follow US law and abide by US court orders.

With the help of these court orders, the US government has already shut down thousands of websites it has declared to be breaking laws about drugs, intellectual property, gambling, and others. Kim Dotcom's Megaupload file-sharing website was also shut down in 2012 due to this.

If you think that domains registered under handles outside of the United States don't come under the US jurisdiction, then you are wrong.

The US government even has international cooperation agreements with many countries, requiring foreign registries to comply with US orders.

The

KickassTorrents

(or KAT.cr) website — the world's most notorious file-sharing sites — is the best example of this kind.

While the main site was registered with the .cr domain by the Costa Rican register called NIC, it was shuttered at the request of the United States this summer and its operator was arrested in Poland and charged by US authorities with varying criminal copyright infringement counts.

US technology giants, including Google, Facebook, Twitter, Yahoo, and Amazon, also back the transition, arguing it will support innovation.

Even former top United States national security officials, Michael Chertoff and James Cartwright, also

support the transition

to ICANN, despite national security fears.



from The Hacker News http://ift.tt/2dtzwWs

Uh oh, Yahoo! Data Breach May Have Hit Over 1 Billion Users


The massive data breach that Yahoo! confirmed to the world last week is claimed by the company to have been carried out by a

"state-sponsored actor"

in 2014, which exposed the accounts of at least

500 Million Yahoo users

.

But, now it seems that Yahoo has downplayed a mega data breach and triying to hide it's own security blunder.

Recently the information security firm InfoArmor that analyzed the data breach refuted the Yahoo's claim,

stating

that the data breach was the work of seasoned cyber criminals who later sold the compromised Yahoo accounts to an Eastern European nation-state.

Over 1 Billion Accounts May Have Been Hacked

Now, there's one more twist in the unprecedented data heist.

A recent advancement in the report indicates that the number of affected Yahoo accounts may be between 1 Billion and 3 Billion.

An unnamed, former Yahoo executive who is familiar with the company's security says that the Yahoo's back-end system's architecture is designed in such a way that all of its products use one main user database (UDB) to authenticate users, Business Insider

reported

Friday.

So all usernames and passwords that users enter to log into services like Yahoo Mail, Sports or Finance goes to this one central database to ensure they are valid, allowing them access.

This central database is what got compromised, and therefore, it's quite difficult to believe that the hackers who compromised the whole database walk away with just a small bunch of

"the core crown jewels of Yahoo customer credentials."

Whoever carried out the hack not only stole usernames and email addresses of affected users but also pilfered other personal information, including their dates of birth, phone numbers, hashed passwords, and unencrypted security answers.

So, it's unclear how Yahoo come up with the 500 Million number.

The company had not commented further on how the

data breach happened

or when it was discovered, citing an active investigation.

Yahoo! could have saved you, but decided not to:

A lengthy report

published

by the New York Times seemingly explains that the company did not reset the passwords of its users after the breach due to the decisions made by Yahoo's CEO Marissa Mayer, who seemed to prioritize developing new products over making security improvements.

The reason sounds stupid, as the article reads:

"The 'Paranoids,' the internal name for Yahoo's security team, often clashed with other parts of the business over security costs. And their requests were often overridden because of concerns that the inconvenience of added protection would make people stop using the company's products."

If Yahoo had reset the passwords of its affected users, proper security measures would have been taken by users to protect their personal data from hackers.

Let's see what new advancements come to this unprecedented data breach.

Already, the Yahoo hack is believed to be one of the biggest in history, and the company is still trying to negotiate a deal to sell its core business to

Verizon for $4.8 Billion

.

Yahoo! has yet to respond to the recent revelation by the insider.

Data breach news has already magnified company's problems, but if breach number reaches Billion, would the company be able to save its acquisition deal?

Let us know in the comments below...



from The Hacker News http://ift.tt/2dfdXLg

Friday, September 30, 2016

Vulnerability Spotlight: OpenJPEG JPEG2000 mcc record Code Execution Vulnerability


Archives



from Cisco Blog » Security http://ift.tt/2dGlX3y

Good Morning Karen. Cool or Scary?

Last month I spoke at a telecommunications industry event. The briefer before me showed a video by the Hypervoice Consortium, titled Introducing Human Technology: Communications 2025. It consists of a voiceover by a 2025-era Siri-like assistant, speaking to her owner, "Karen." The assistant describes what's happening with Karen's household. 15 seconds into the video, the assistant says:

The report is due today. I've cleared your schedule so you can focus. Any attempt to override me will be politely rebuffed.

I was already feeling uncomfortable with the scenario, but that is the point at which I really started to squirm. I'll leave it to you to watch the rest of the video and report how you feel about it.

My general conclusion was that I'm wary of putting so much trust in a platform that is likely to be targeted by intruders, such that they can manipulate so many aspects of a person's life. What do you think?

By the way, the briefer before me noted that every vision of the future appears to involve solving the "low on milk problem."

Copyright 2003-2015 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)


from TaoSecurity http://ift.tt/1F6TGyg

USN-3090-2: Pillow regresssion

Ubuntu Security Notice USN-3090-2

30th September, 2016

Pillow regression

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 14.04 LTS

Software description

  • pillow - Python Imaging Library compatibility layer

Details

USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.

We apologize for the inconvenience.

Original advisory details:

It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)

Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)

Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 14.04 LTS:
python-imaging 2.3.0-1ubuntu3.3
python3-pil 2.3.0-1ubuntu3.3
python-pil 2.3.0-1ubuntu3.3
python3-imaging 2.3.0-1ubuntu3.3

To update your system, please follow these instructions: http://ift.tt/17VXqjU.

None

References

CVE-2014-9601, LP: 1628351



from Ubuntu Security Notices http://ift.tt/2cHE6fd

UK banking chief raises concerns over security of biometric authentication


Biometric data is increasingly playing a strategic role in end-user authentication, and banking regulators in the UK are concerned just how secure it might be in light of a recent report by Kaspersky Lab.

In an investigation into underground cybercrime, Kaspersky found at least 12 sellers offering ATM skimmers capable of stealing fingerprints. Furthermore, Kaspersky identified three underground sellers researching devices that could obtain data from palm vein and iris recognition systems.

The report drew the attention of the UK's Treasury Select Committee, which oversees treasury, revenue and customs, and the Bank of England.

The committee's chief, Andrew Tryie, is asking banking regulators to look into consequences surrounding stolen biometric data. In a letter to industry and government, he said, "Banks and regulators will need to plan for what they will do if biometric details are lost and/or illegally obtained by third parties." He asked regulators if they shared his concerns, and he went on to say plans would need to be developed to deal with customers who may be victims of biometric hacks.

The main concern with biometric identifiers is that they cannot be revoked and replaced by a new identifier like in the case of a stolen password.

The concern is real in the US where 5.6 million fingerprint records were stolen during the breach of the United States Office of Personnel Management in the summer of 2015. US agencies created a working group to see how cyber attackers could use fingerprint data. This group includes the FBI, Department of Homeland Security, Department of Defense, and other members of the intelligence community.

"The problem with biometrics is that unlike passwords or pin codes, which can be easily modified in the event of compromise, it is impossible to change your fingerprint or iris image," Olga Kochetova, security expert at Kaspersky Lab, said in a release surrounding the Kaspersky investigation. "Thus, if your data is compromised once, it won't be safe to use that authentication method again. That is why it is extremely important to keep such data secure and transmit it in a secure way."

Kaspersky Lab also reported discussions in underground communities regarding development of mobile applications that rely on placing masks over a human face. With such an app, attackers can take a person's photo posted on social media and use it to fool a facial recognition system, the report said.



from Latest Topic for ZDNet in... http://ift.tt/2d1V1u9

Google Releases Security Update for Chrome

Original release date: September 30, 2016

Google has released Chrome version 53.0.2785.143 to address multiple vulnerabilities for Windows, Mac, and Linux. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.

US-CERT encourages users and administrators to review the Chrome Releases page and apply the necessary update.


This product is provided subject to this Notification and this Privacy & Use policy.




from US-CERT National Cyber Alert System http://ift.tt/2dt5BtG