Connect with us

Security

GitHub launches ‘Security Lab’ to help secure open source ecosystem

Published

on

Today, at the GitHub Universe developer conference, GitHub announced the launch of a new community program called Security Lab that brings together security researchers from different organizations to hunt and help fix bugs in popular open source projects.

“GitHub Security Lab’s mission is to inspire and enable the global security research community to secure the world’s code,” the company said in a press release.

“Our team will lead by example, dedicating full-time resources to finding and reporting vulnerabilities in critical open source projects,” it said.

Founding members include security researchers from organizations like Microsoft, Google, Intel, Mozilla, Oracle, Uber, VMWare, LinkedIn, J.P. Morgan, NCC Group, IOActive, F5, Trail of Bits, and HackerOne.

GitHub says Security Lab founding members have found, reported, and helped fix more than 100 security flaws already.

Other organizations, as well as individual security researchers, can also join. A bug bounty program with rewards of up to $3,000 is also available, to compensate bug hunters for the time they put into searching for vulnerabilities in open source projects.

Bug reports must contain a CodeQL query. CodeQL is a new open source tool that GitHub released today; a semantic code analysis engine that was designed to find different versions of the same vulnerability across vasts swaths of code. Besides GitHub, CodeQL is already being rolled out in other places to help with vulnerability code scans, such as Mozilla.

SolarWinds® Network Insight for Cisco ASA goes beyond basic up/down status. It can help provide comprehensive firewall performance, and also offers access control list monitoring.Downloads provided by SolarWinds

GitHub’s new Security Lab project did not come out of the blue. Efforts have been going on at the company to improve the overall security state of the GitHub ecosystem for some time. Security Lab merges all these together.

For example, GitHub has been working for the past two years on rolling out security notifications that warn project maintainers about dependencies that contain security flaws.

Earlier this year, GitHub started testing a feature that would enable project authors to create “automated security updates.” When GitHub would detect a security flaw inside a project’s dependency, GitHub would automatically update the dependency and release a new project version on behalf of the project maintainer.

The feature has been in beta testing for all 2019, but starting today automated security updates are generally available and have been rolled out to every active repository with security alerts enabled. [Also see official announcement.]

github-automated-fixes.png
Image: GitHub

Furthermore, GitHub also recently became an authorized CVE Numbering Authority (CNA), which means it can issue CVE identifiers for vulnerabilities. GitHub didn’t apply to become a CNA for nothing.

Its CNA capability has been added to a new service feature called “security advisories.” These are special entries in a project’s Issues Tracker where security flaws are handled in private.

Once a security flaw is fixed, the project owner can publish the security, and GitHub will warn all upstream project owners who are using vulnerable versions of the original maintainer’s code.

But before publishing a security advisory, project owners can also request and receive a CVE number for their project’s vulnerability directly from GitHub.

Previously, many open source project owners who hosted their projects on GitHub didn’t bother requesting a CVE number due to the arduous process.

However, getting CVE identifiers is crucial, as these IDs and additional details can be integrated into many other security tools that scan source code and projects for vulnerabilities, helping companies detect vulnerabilities in open sourcec tools that they would have normally missed.[Also see official announcement.]

github-cve-advisory.png
Image: GitHub

And in addition to the new GitHub Security Lab, the code-sharing platform is also launching the GitHub Advisory Database, where it will collect all security advisories found on the platform, to make it easier for everyone to keep track of security flaws found in GitHub-hosted projects. [Also see official announcement.]

And last, but not least, GitHub also updated Token Scanning, its in-house service that can scan users’ projects for API keys and tokens that have been accidentally left inside their source code.

Starting today, the service, which previously could detect API tokens from 20 services, can identify four more formats, from GoCardless, HashiCorp, Postman, and Tencent. [Also see official announcement.]

Source: https://www.zdnet.com/article/github-launches-security-lab-to-help-secure-open-source-ecosystem/

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Security

Apple head of security accused of offering iPads as bribes for concealed gun permits

Published

on

By

A California grand jury has indicted Apple’s head of global security on charges that he tried to bribe Santa Clara County officials to procure firearms (CCW) licenses, according to a news release. Santa Clara district attorney Jeff Rosen alleges that Thomas Moyer offered 200 iPads — worth about $70,000 — to Capt. James Jensen and Undersheriff Rick Sung in the Santa Clara County sheriff’s office, in exchange for four concealed firearms licenses for Apple employees.

The charges came after a two-year investigation. “In the case of four CCW licenses withheld from Apple employees, Undersheriff Sung and Cpt. Jensen managed to extract from Thomas Moyer a promise that Apple would donate iPads to the Sheriff’s Office,” Rosen said in the news release. The iPads were never delivered, according to Rosen’s office, because Sung and Moyer became aware in 2019 that the district attorney was executing a search warrant for the sheriff department’s CCW records.

Moyer’s attorney, Ed Swanson, said in a statement emailed to The Verge that his client is innocent of the charges filed against him, adding he believed Moyer was “collateral damage” in a dispute between the Santa Clara sheriff and district attorneys’ offices. “He did nothing wrong and has acted with the highest integrity throughout his career,” Swanson said. “We have no doubt he will be acquitted at trial.”

“We expect all of our employees to conduct themselves with integrity,” an Apple spokesperson said in a statement to Ars Technica. “After learning of the allegations, we conducted a thorough internal investigation and found no wrongdoing.”

According to Bloomberg News, Moyer has been at Apple for about 15 years and has been its head of global security since November 2018. He wrote a memo in 2018 warning Apple employees about the potential consequences of leaking information to the media, which he wrote “can become part of your personal and professional identity forever.”

Source: https://www.theverge.com/2020/11/23/21611525/apple-ipads-bribes-concealed-gun-permits-security-head-accused-santa-clara

Continue Reading

Security

Be Very Sparing in Allowing Site Notifications

Published

on

By

An increasing number of websites are asking visitors to approve “notifications,” browser modifications that periodically display messages on the user’s mobile or desktop device. In many cases these notifications are benign, but several dodgy firms are paying site owners to install their notification scripts and then selling that communications pathway to scammers and online hucksters.

Notification prompts in Firefox (left) and Google Chrome.

When a website you visit asks permission to send notifications and you approve the request, the resulting messages that pop up appear outside of the browser. For example, on Microsoft Windows systems they typically show up in the bottom right corner of the screen — just above the system clock. These so-called “push notifications” rely on an Internet standard designed to work similarly across different operating systems and web browsers.

But many users may not fully grasp what they are consenting to when they approve notifications, or how to tell the difference between a notification sent by a website and one made to appear like an alert from the operating system or another program that’s already installed on the device.

This is evident by the apparent scale of the infrastructure behind a relatively new company based in Montenegro called PushWelcome, which advertises the ability for site owners to monetize traffic from their visitors. The company’s site currently is ranked by Alexa.com as among the top 2,000 sites in terms of Internet traffic globally.

Website publishers who sign up with PushWelcome are asked to include a small script on their page which prompts visitors to approve notifications. In many cases, the notification approval requests themselves are deceptive — disguised as prompts to click “OK” to view video material, or as “CAPTCHA” requests designed to distinguish automated bot traffic from real visitors.

An ad from PushWelcome touting the money that websites can make for embedding their dodgy push notifications scripts.

Approving notifications from a site that uses PushWelcome allows any of the company’s advertising partners to display whatever messages they choose, whenever they wish to, and in real-time. And almost invariably, those messages include misleading notifications about security risks on the user’s system, prompts to install other software, ads for dating sites, erectile disfunction medications, and dubious investment opportunities.

That’s according to a deep analysis of the PushWelcome network compiled by Indelible LLC, a cybersecurity firm based in Portland, Ore. Frank Angiolelli, vice president of security at Indelible, said rogue notifications can be abused for credential phishing, as well as foisting malware and other unwanted applications on users.

“This method is currently being used to deliver something akin to adware or click fraud type activity,” Angiolelli said. “The concerning aspect of this is that it is so very undetected by endpoint security programs, and there is a real risk this activity can be used for much more nefarious purposes.”

Sites affiliated with PushWelcome often use misleading messaging to trick people into approving notifications.

Angiolelli said the external Internet addresses, browser user agents and other telemetry tied to people who’ve accepted notifications is known to PushWelcome, which could give them the ability to target individual organizations and users with any number of fake system prompts.

Indelible also found browser modifications enabled by PushWelcome are poorly detected by antivirus and security products, although he noted Malwarebytes reliably flags as dangerous publisher sites that are associated with the notifications.

Indeed, Malwarebytes’ Pieter Arntz warned about malicious browser push notifications in a January 2019 blog post. That post includes detailed instructions on how to tell which sites you’ve allowed to send notifications, and how to remove them.

KrebsOnSecurity installed PushWelcome’s notifications on a brand new Windows test machine, and found that very soon after the system was peppered with alerts about malware threats supposedly found on the system. One notification was an ad for Norton antivirus; the other was for McAfee. Clicking either ultimately led to “buy now” pages at either Norton.com or McAfee.com.

Clicking on the PushWelcome notification in the bottom right corner of the screen opened a Web site claiming my brand new test system was infected with 5 viruses.

It seems likely that PushWelcome and/or some of its advertisers are trying to generate commissions for referring customers to purchase antivirus products at these companies. McAfee has not yet responded to requests for comment. Norton issued the following statement:

“We do not believe this actor to be an affiliate of NortonLifeLock. We are continuing to investigate this matter. NortonLifeLock takes affiliate fraud and abuse seriously and monitors ongoing compliance. When an affiliate partner abuses its responsibilities and violates our agreements, we take necessary action to remove these affiliate partners from the program and swiftly terminate our relationships. Additionally, any potential commissions earned as a result of abuse are not paid. Furthermore, NortonLifeLock sends notification to all of our affiliate partner networks about the affiliate’s abuse to ensure the affiliate is not eligible to participate in any NortonLifeLock programs in the future.”

Requests for comment sent to PushWelcome via email were returned as undeliverable. Requests submitted through the contact form on the company’s website also failed to send.

While scammy notifications may not be the most urgent threat facing Internet users today, most people are probably unaware of how this communications pathway can be abused.

What’s more, dodgy notification networks could be used for less conspicuous and sneakier purposes, including spreading fake news and malware masquerading as update notices from the user’s operating system. I hope it’s clear that regardless of which browser, device or operating system you use, it’s a good idea to be judicious about which sites you allow to serve notifications.

If you’d like to prevent sites from ever presenting notification requests, check out this guide, which has instructions for disabling notification prompts in Chrome, Firefox and Safari. Doing this for any devices you manage on behalf of friends, colleagues or family members might end up saving everyone a lot of headache down the road.

Source: https://krebsonsecurity.com/2020/11/be-very-sparing-in-allowing-site-notifications/

Continue Reading

Security

How to Secure IoT Devices–Right Now

Published

on

By

IoT devices are not going away any time soon. The estimates vary widely as to how many devices are currently in use, and how many devices will be deployed in the next few years, but the one thing that everybody seems to agree on is that IoT adoption is on the rise. The other thing people seem to agree on is that it is critical to secure IoT devices–using long-term and short-term strategies.

Early on, many IoT vendors rushed their products to market with seemingly no concern about security. Things seem to be getting better, but IoT’s reputation for being insecure has been firmly cemented. That makes IoT devices a big target, so it makes sense to consider what you can do–right now–to keep secure IoT devices.

1. Perform a password audit.

The very first thing I recommend doing to secure IoT devices is to perform a password audit against all of your IoT devices. While it is important to determine whether any of your devices are using weak passwords, it is far more important to test for default password use. Remember, nearly every device manufacturer posts its manuals online, and these manuals almost always list the default password for the device. Anyone can get access to this information, and default passwords are often a starting point for those who seek to compromise IoT devices.

Ideally, each of your IoT devices should be equipped with a random, but complex password. After all, if all of your devices share a common password, an attacker could conceivably acquire that password and take control of all of the devices. This is especially troubling since there are stories of attackers who have managed to get IoT devices to function as botnets.

2. Review the end user agreement.

One of the things that I never hear anyone talk about with regard to IoT security is the importance of reviewing the end user agreement. That’s the agreement that the manufacturer displays on screen when you initially configure the device. If you simply click OK to accept the agreement without reading it–so you can finish the deployment and get on with your day–you really don’t know what you have just agreed to. Given the extent to which devices have become known for spying, it may be worth taking the time to review the end user agreement for your devices and make sure that the device is not compromising sensitive information. If you’re not comfortable with something in the end user agreement, it may be worth adopting a competing vendor’s product.

3. Keep firmware up to date.

Just as software vendors routinely release patches for their products, reputable IoT vendors will occasionally release firmware updates to secure IoT devices. It is important to download, test and deploy these firmware updates just as you would any other patch.

4. Disable unnecessary features.

In some cases, you can enhance your security by disabling unnecessary features. To determine what’s really necessary and what’s not, spend time reviewing the feature sets of the IoT devices that you use.

Obviously, some devices are far more feature-rich than others. An IP-enabled industrial sensor, for instance, probably has few, if any, ancillary features. On the other hand, devices that are oriented more toward the end user tend to be feature-rich. In some cases, disabling even a single feature can significantly improve the device’s overall security.

For example, like many other people, I have a Wi-Fi enabled, smart thermostat in my home. This thermostat has a remote access feature that lets me remotely monitor the temperature in my home and make adjustments if necessary. I have disabled the thermostat’s remote access feature–not because I’m worried about a hacker setting the air conditioner to run at full blast, but because an attacker who gains access to the thermostat could conceivably use it as a platform for launching an attack against other devices on the network.

5. Put segmentation to use.

My goal for this blog post was to focus on immediate actions that can be taken in an effort to secure IoT devices. Even so, I just couldn’t conclude the post without mentioning segmentation. Segmentation takes some planning, so it doesn’t really qualify as something that you can do right now. Even so, segmentation is one of the most important things that you can do to keep your IoT devices secure, so I wanted to be sure to mention it.

When possible, place your IoT devices on isolated network segments. The smart thermostat I mentioned is connected to a dedicated Wi-Fi network that services only the connected devices in my home. Using this dedicated network prevents IoT devices from accessing sensitive data such as the files stored on my laptop.

Even if you cannot completely isolate a device, you may be able to use firewall and routing policies to restrict a device’s communications. For example, if a particular device communicates with a backend SQL Server, you should look for ways to prevent the device from ever communicating with anything else (with the possible exception of a management PC). This can go a long way toward keeping the device secure while also preventing data leakage.

Source: https://www.itprotoday.com/mobile-management-and-security/how-secure-iot-devices-right-now

Continue Reading
Advertisement

Trending

Copyright © 2020 Inventrium Magazine

%d bloggers like this: