Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Sunday, April 7, 2019

Woesnotgone Meadow; April 5, 2019


In the Meadow, we are online quite frequently. One headache the residents have dealt with has been with passwords. Some of our residents have found it difficult to remember all the passwords they have for the different sites. Most of the residents have begun using a password manager. Margie from the library recommended using a password manager. Generally, these work fine. This was not the case, however, with Blur.

Abine is the corporate entity behind Blur, a password manager, and DeleteMe, an online privacy protection service. Abine functions to encrypt the user’s passwords used with Blur. Blur’s service is to improve the user’s privacy with its secure password management service.

There was a rather significant compromise recently. This was not actually an attack, but more of a case of negligence. A reasonably prudent person would secure the cloud platform where the data was located. If the person was not exactly secure on how to do this, they would then research this or hire a party to do this. After all, the company is the steward of the data and is responsible for it.

This did not exactly happen here. An Amazon S3 storage bucket contained the subject file. This was unfortunately misconfigured. On December 13, 2018, the business was notified by a security researcher there was an issue. The business had no idea. A server was accessible and exposed a file with sensitive client information. The business, post-notification, did examine this, as you would expect instead of just taking the word of a researcher, and found the assertion was correct. This was announced on their business blog.

Of all the potential companies to have an insecure file open and accessible, this was the one. This should not have been misconfigured and insecure, given what the company focused on.

In this specific instance, there were 2.4M Blur users affected. The affected users were the ones who registered prior to January 6, 2018. The user data was left exposed and accessible. This included the user’s email address, a portion of the user’s first and left name, the user’s password hints, the user’s last two IP addresses used to login for the Blur app, and the user’s encrypted password. In this case, no DeleteMe user data was involved.

As noted, this was not exactly an attack. The data was openly exposed and accessible, however, there was no direct evidence the data was exfiltrated.

This was another example of a misconfigured AWS bucket which was not configured correctly. There may have been a time issue, or other factors involved. One of the managers should have actually reviewed this, and not just checked the box.

Resources
Abrams, L. (2019, January 2). Abine blur password manager user data exposed online. Retrieved from https://www.bleepingcomputer.com/news/security/abine-blur-password-manager-user-data-exposed-online/

Cimpanu, C. (2019, January 2). Data of 2.4 million blur password manager users left exposed online. Retrieved from https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/

Smith, A. (2019, January 2). Data on 2.4M gbine blur user’s ‘potentially exposed’. Retrieved from https://www.pcmag.com/news/365672/blur-users-personal-details-potentially-exposed


Waqas. (2019, January 3). Abine blur password manager exposed data of 2.4M users. Retrieved from https://www.hackread.com/abine-clur-password-manager-exposed-data-of-users/

Friday, November 23, 2018

Air Canada Compromised!

Each country has its own set of airlines servicing its area. Based on the market, certain countries have more or less than the others. These fly throughout their respective nation and world. Most persons, as a national course of business, go online, enter their information, including credit card numbers, to purchase the airline tickets. This occurs throughout the globe every single day without an issue. An option also is to do this with a mobile device.

Issue
Air Canada has a number of users purchasing tickets. A portion of these purchases are done on a mobile device using the mobile app. These were the focus of the attack. A subset of these, who had entered into the system their passport information, may have had their data stolen.

Attack
Air Canada had been previously criticized for their weak password system. The prior convention used was 6-10 characters (letters and numbers), but no other symbols. With this possibly short passwords in place, there are two issues. One is the lack of complexity with the acceptable passwords, and the other is the potential for the users to use these passwords across multiple domains. In comparison, the official guidance from the Canadian government is for passwords to have a minimum length of eight characters and at least one character that is not a letter or number. Seemingly, Air Canada would have followed the guidance from their own government.

After the attack Air Canada required the password to be at least 10 characters and one symbol. Air Canada was not sure yet how the mobile app breach occurred. This was a relatively serious issue as approximately 20k account’s data is believed to have been stolen. This is approximately 1% of their clientele. The data did not include the credit card details, as these were encrypted. This did include the client’s name, email address(es), phone numbers, passport numbers, passport country of issuance, expiration date, nationality, gender, and country of residence.

This list is rather substantial and the data someone would need to assume another’s identity. Also the attackers, or persons subsequently with this data could set up other accounts at banks, open credit cards, and other actions which would negatively impact the user’s credit scores.

On a tangent, Air Canada did however respond quickly to the issue. Their effort is applauded. The business also updated the password convention to a more appropriate level.

Indications
The attack and compromise would not have been something unknown for an extended period. There had been a large, unusual level of activity between August 22-24, 2018. This was in the form of the large number of log-ins during this period. The volume was well outside of the normal value, even with a margin of error attached.

Remediation
The airline, to be thorough, locked down the entirety of the 1.7M accounts. The management did not want subsequent issues continuing if a handful of the accounts were missed. In order to continue to use the service, the users would need to reset their password to access their account again.

Lessons
Passwords are a touchy subject with users. The users want passwords that are easy to remember and short. In the alternative, the users would like to not use passwords at all. However, some form of authentication is required. For the users, dependent on the use case, a password manager or generator may work well. Also using MFA would be beneficial.




Resources

BBC News. (2018, August 29). Air canada app data breach involves passport numbers. Retrieved from https://www.bbc.co.uk/news/technology-45349056

Constantin, L. (2018, August 30). Hackers access data. Retrieved from https://securityboulevard.com/2018/08/air-canada-resets-customers-passwords-after-hackers-access-data/

Dunn, J.E. (2018, August 30). Air canada resets 1.7 million accounts after app breach . Retrieved from https://nakedsecurity.sophos.com/2018/08/30/air-canada-resets-1-7-million-accounts-after-app-breach/

Evans, P. (2018, August 29). Air canada mobile app breach affects 20,000 people. Retrieved from https://www.cbc.ca/news/business/air-canada-mobile-app-1.4802879

Johnson, B. 92018, August 30). All 1.7 million air canada app users must reset passwords after breach. Retrieved from https://www.itworldcandda.com/article/all-1-7-million-air-canada-app-users-must-reset-password-after-breach/

Osborne, C. (2018, August 30). Air canada reveals mobile data breach, passport numbers potentially exposed. Retrieved from https://www.zdnet.com/article/air-canda-reveals-mobile-data-breach-passport-numbers-potentially-exposed/

Reynolds, C. (2018, August 29). Air canada says mobile app breach may affect up to 20,000 customers. Retrieved from https://www.ctvnews.ca/business/air-canda-says-mobile-app-breach-may-affect-up-to-20-000-customers-1.4072467

Seals, T. (2018, August 30). Travel breaches hit air canada and asia-pac hotelier. Retrieved from https://threatpost.com/travel-breaches-hit-air-canda-and-asia-pac-hotelier/137059/

Security Experts. (2018, August 30). Air canada breach. Retrieved from https://www.informationsecuritybyzz.com/expert-comments/security-experts-comments-air-canada-breach/

Whittaker, Z. (2018, August 29). Air canada confirms mobile app data breach. Retrieved from https://techcrunch.com/2018/08/29/air-canada-confirms-mobile-app-data-breach/

Monday, October 22, 2018

Ed tech targeted!



Chegg Inc. is a publicly traded company, which went public in 2013. The company, based in the US, rents online textbooks, and offers tutorials. Thus, the company does hold and manage sensitive and confidential client information. As this is the case, and the data is very marketable, the company would naturally be a target.

Issue!
The company was targeted and experienced a data breach. Chegg learned of the breach on September 19, 2018. This is the good news. The company could not have known about this breach at all, and the clients could have been none the wiser. The company detecting this was good for the parties involved. The bad news is the breach occurred on or about April 9, 2018. The attackers could have been in the company's systems for months, unfettered and acquiring the information they wanted. The attackers had the potential to harvest all the data they wanted. Chegg began to notify the affected clients on September 26, 2018. The notice stated the clients' data and other information had been accessed.

This compromise, beginning in late April 2018 by an unauthorized party or group accessed a company database with their user's data, including the names, emails, shipping addresses, and hashed passwords. Granted the passwords being hashed is a good thing. The curiosity and potential issue is the hashing algorithm was not disclosed. This could have been very weak, and subsequently vulnerable. This also affected the data of its subsidiary Easybib.

Remediation
This was a rather serious breach. Due to the client's information being accessed by the unauthorized party, Chegg needed to reset the passwords. This was a rather substantial project, as there were 40M users overall who needed to do this.


Resources
Cimpanu, c. (2018, September 26). Chegg to reset passwords for 40 million users after April 2018 hack. Retrieved from https://www.zdnet.com/article/chegg-to-reset-passwords-for-40-users-after-april-2018-hack/

Pymnts. (2018, September 27). Chegg hack hits 40M customers. Retrieved from https://www.pymnts.com/news/securityandrisk/2018/chegg-data-breach/

Reed, J.R. (2018, September 26). Ed tech company chegg plunges after disclosing data breach. Retrieved from https://www.cnbc.com/2018/09/26/ed-tech-company-chegg-plunges-after-disclosing-data-breach.html

Reed, J.R. (2018, September 26). Online textbook rental and tutorial company chegg plunges after disclosing data breach. Retrieved from https://sg.finance.yahoo.com/news/online-textbook-rental-tutorial-company-191100361.html

Securities and Exchange Commissioner (SEC). (2018, September 25). Form 8-K. Retrieved from https://www.sec.gov/Archives/edgar/data/1364954/000136495418000187/cyrus.htm

Surran, C. (2018, September 26). Chegg -12% after disclosing data breach; reaffirms Q3 guidance. Retrieved from https://seekingalpha.com/news/3393207-chegg-minus-12-percent-disclosing-data-breach-reaffirms-q3-guidance