This is the first post of a – potential – series of rants on ubiquitous pieces
of crap (security-wise), bothering pretty much every ISO I know.
I’m talking about “common desktop applications” and today’s topic is going to be
the beloved Adobe Flash Player. Some of you who had the opportunity (or
imposition 😉 to listen to one my talks covering “modern enterprise security
space” (e.g.
this one)
might remember me saying sth like “If a fairy godmother turned up and asked me
for three things to get rid of in order to enhance overall corporate information
security in a sustainable way, my answers would be…” and then giving Adobe Flash
as the first mention. (before you ask: amongst the other candidates are Apple
Quicktime, Windows GDI and “Javascript in Acrobat Reader”).
Some reflections on virtualization security, part 1
Today was an interesting day, for a number of reasons. Amongst those it stuck
out that we were approached by two very large environments (both > 50K
employees) to provide security review/advise, as they want to “virtualize their
DMZs, by means of VMware ESX”.
[yes, more correctly I could/should have written: “virtualize some of their DMZ
segments”. but this essentially means: “mostly all of their DMZs” in 6-12
months. and “their DMZ backend systems together with some internal servers” in
12-24 months. and “all of this” in 24-36 months. so it’s the same discussion
anyway, just on a shifted timescale ;-)]
New SSL/TLS MiTM Attacks
A number of customers has approached us with questions like “Those new MiTM
attacks against SSL/TLS, what’s their impact as for the security of our SSL VPNs
with client certificates”?
In the following we give our estimation, based on the information publicly
available as of today.
On 11/04/09 two security researchers (Marsh Ray and Steve Dispensa) published a
paper describing some
previously (presumably/hopefully) unknown MiTM attacks against SSL/TLS.
CVE-2009-3555 was assigned to the underlying vulnerabilities within SSL/TLS.
The attacks described might potentially allow an attacker to hijack an
authenticated user’s (SSL/TLS) session. In an
IETF draft
published 11/09/09 and describing a potential protocol extension intended to
mitigate the attacks the following is stated:
“SSL and TLS renegotiation are vulnerable to an attack in which the attacker
forms a TLS connection with the target server, injects content of his choice,
and then splices in a new TLS connection from a client. The server treats the
client’s initial TLS handshake as a renegotiation and thus believes that the
initial data transmitted by the attacker is from the same entity as the
subsequent client data.”
If they had used DLP…
…
this
would not have happened. At least this is what $SOME_DLP_VENDOR might tell
you.
Maybe, maybe not. It wouldn’t have happened if they’d followed “common security
best practices” either. Like “not to process sensitive data on (presumably)
private laptops” or “not to run file sharing apps on organizational ones” or
“not to connect to organizational VPNs and home networks simultanously”. yadda
yadda yadda.
Series on “Outdated Threat Models” – Part 1
Yesterday I took a long run (actually I did the full distance here) and usually such exercises are good opportunities to “reflect on the world in general and the infosec dimension of it in particular”… at least as long as your blood sugar is still on a level to support somewhat reasonable brain activity 😉
Anyhow, one of the outcomes of the number of strange mental stages I went through was the idea of a series of blogposts on architectural or technological approaches that are widely regarded as “good security practice” but may – when looked at with a bit more of scrutiny – turn out to be based on what I’d call “outdated threat models”.
Continue reading Continue readingWelcome to insinuator.net
Welcome to insinuator.net, the semi-official blog of
ERNW Enno Rey Netzwerke GmbH.
You may ask: Why yet another infosec blog? Aren’t there already just too many
around? Well, possibly. But that opulence is part of blogging in general, isn’t
it? 😉
Given we are trying to contribute to “public space & opinion” in a number of ways anyway [e.g. by our presentations or our newsletter] it seemed just too logical – and we’ve been asked by various people as well – to add another element to global blogosphere. Voilà, here we go!
Continue reading Continue reading