Auracast, the new Bluetooth LE Broadcast Audio feature has gained some publicity
in the past months. The Bluetooth SIG has introduced the LE Audio feature-set to
the Bluetooth 5.2 Specification in 2019 and vendors are only now starting to
implement it. Auracast facilitates broadcasting audio over Bluetooth LE to a
potentially unlimited number of devices. It does not require pairing or
interaction between the sender and the receivers.
We also presented this topic
at 38c3.
This blog post will contain similar contents albeit with some more details.
A new ERNW whitepaper was just published. I wrote this whitepaper in the course
of my bachelor thesis and it examines multi-factor authentication in Microsoft
Windows environments:
Credential theft and the subsequent reuse of stolen credentials are a
significant problem in today’s information security. To counter the associated
risks, a planned approach is required as part of a comprehensive security
architecture program. This includes the implementation of multi-factor
authentication as an important building block. This whitepaper covers the
relevant steps of implementing a multi-factor authentication system in an
enterprise environment and closes with a security evaluation.
It’s been a long time… we just published an
ERNW Newsletter. Here’s
the abstract:
In order to protect sensitive data on corporate laptops, most companies are
using full disk encryption solutions. While native encryption products like
Microsoft Bitlocker, Apple FileVault and open source solutions like TrueCrypt
were already heavily scrutinized by security researchers, many popular
commercial third party products are to some point still black boxes.
In this paper, we discuss Check Point Full Disk Encryption (FDE) with active
“Windows Integrated Logon”. Checkpoint FDE is a software package that is part of
Check Point Endpoint Security and offers full disk encryption on Microsoft
Windows and Mac OS X systems. The “Windows Integrated Logon” feature reduces
total cost of ownership by disabling pre-boot authentication. Check Point
themselves warn about security risk associated with using this feature.
We recently performed a Proof-of-Concept (PoC) implementation of certificate
based auth with iPads in some large environment. So far the focus has been
mainly on WLAN access; VPN and EAS authentication are going to follow in the
next step.
As we figure that the topic might be of interest for some of you, we’ve
extracted a certain, not-too-customer-specific part of the deliverable and
converted it into an
ERNW newsletter.
Special thanks go to Rene Graf for leading the project! 😉
Yesterday I took a long run (actually I did the full distance
here) and usually such exercises are good
opportunities to “reflect on the world in general and the infosec dimension of
it in particular”… at least as long as your blood sugar is still on a level to
support somewhat reasonable brain activity 😉
Anyhow, one of the outcomes of the number of strange mental stages I went
through was the idea of a series of blogposts on architectural or technological
approaches that are widely regarded as “good security practice” but may – when
looked at with a bit more of scrutiny – turn out to be based on what I’d call
“outdated threat models”.